lab52 · Crawled Oct 2, 2026

Backdoors in the Dungeon – TURN & MQTT Abused by DragonForce

22 IoCs 1 Actors
Read original article ↗

AI Summary

DragonForce, a ransomware-as-a-service (RaaS) operation, has been observed deploying two backdoors that abuse legitimate infrastructure for command and control (C2) communications. The first backdoor operates in-memory and uses TURN servers, including Microsoft Teams infrastructure, to blend malicious traffic with legitimate traffic. The second backdoor ensures persistence via DLL sideloading and scheduled tasks, using both TURN and MQTT as redundant C2 channels. The malware employs encryption, obfuscation, and in-memory execution to evade detection and maintain access on compromised systems.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 22 extracted

Type Value Detail
SHA-256 f8eabae53e9dc8c529b6e38c58040ff28a07728cb5e896e16fb64e84bed5cd88 Details →
SHA-256 e9cd052f2d9514d40235ec04c9592f4274d0a4161b846e59bbb5a1a2c806a1c5 Details →
SHA-256 6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4 Details →
SHA-256 1657b22a553feae422dab77886ac60c06b8fad7cbd2cfaf482ba9066ba9922be Details →
SHA-256 5275579f539812ff66d060e12c9b7e99a22c625018f1aae9c5642ab0ba058ccb Details →
SHA-256 c91852bfb8f1d428875595c14cfada8fb234483adb8c6ba78ca2b5ae2a0683e2 Details →
SHA-256 01d638ddd9d780e934305422bc9ee8fa3a5b3163ba66514ae5e5a34ff24df9db Details →
Filename jli.dll Details →
Filename 25vtps.txt Details →
Filename dldwuibjn_chShllcodeTrn.txt Details →
Filename dldwuibjn_chShllcodeTrn.bin Details →
Filename rvsdiqw.txt Details →
IP 188[.]190[.]4[.]111 Details →
IP 62[.]164[.]177[.]145 Details →
IP 217[.]156[.]8[.]181 Details →
Domain accesscapfunding[.]com Details →
Domain paigeinfull[.]com Details →
Domain cncluxurywater[.]com Details →
Domain printpro[.]com[.]pl Details →
Domain pymsolutions[.]com[.]ar Details →
Domain whapido[.]com[.]ar Details →
Domain prolabgest[.]it Details →

MITRE ATT&CK TTPs 51 techniques

T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1052.001 Exfiltration over USB · Exfiltration T1053 Scheduled Task/Job · Execution T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1132 Data Encoding · Command And Control T1133 External Remote Services · Persistence T1134 Access Token Manipulation · Defense Evasion T1134.001 Token Impersonation/Theft · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1202 Indirect Command Execution · Defense Evasion T1210 Exploitation of Remote Services · Lateral Movement T1218.002 Control Panel · Defense Evasion T1219 Remote Access Software · Command And Control T1222 File and Directory Permissions Modification · Defense Evasion T1484 Domain or Tenant Policy Modification · Defense Evasion T1484.001 Group Policy Modification · Defense Evasion T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1490 Inhibit System Recovery · Impact T1491 Defacement · Impact T1542 Pre-OS Boot · Defense Evasion T1543.002 Systemd Service · Persistence T1543.003 Windows Service · Persistence T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1566 Phishing · Initial Access T1569.002 Service Execution · Execution T1573 Encrypted Channel · Command And Control T1574.001 DLL Search Order Hijacking · Persistence T1586 Compromise Accounts · Resource Development T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1595 Active Scanning · Reconnaissance T1659 Content Injection · Initial Access