security-com · Crawled Aug 1, 2026

Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden

33 IoCs 1 Actors
Read original article ↗

AI Summary

The DragonForce ransomware group, tracked by Symantec as Hackledorb, conducted a sophisticated attack against a U.S. services firm, leveraging custom malware and novel techniques to evade detection. The attackers used a Go-based backdoor named Backdoor.Turn, which abuses Microsoft Teams' TURN relay infrastructure to hide command-and-control (C2) traffic behind legitimate Microsoft domains. They also employed DLL sideloading, BYOVD techniques exploiting vulnerable signed drivers—including Huawei’s HWAuidoOs2Ec.sys—and modified system configurations for persistence and lateral movement before deploying the DragonForce ransomware payload.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 33 extracted

Type Value Detail
SHA-256 82b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013b Details →
SHA-256 821da79d727351dd67ce5df7950e9a3de6647a3cf474bb3a093f67507fed92a6 Details →
SHA-256 b6628d201c2a68d2a3de2a87de7a5acfe21b101a97928e1c8d5c82102d967383 Details →
SHA-256 ce66b8221446c9b6d83f0ce6382f430e519601641e5daaaf1ca7a8a8806cb0b0 Details →
SHA-256 f174c19902523dcf005fa044b6598403a5e5c0a5982398d1bc0dcc5ec1cd351b Details →
SHA-256 142bac0e2148e0d47891b6cd7311195c4acbe33b700fad54a201c52a2bc46219 Details →
SHA-256 8395b621bb4415090f232c59fc41d24ea41a519b58eabe512f3ae7d2fdf049a3 Details →
SHA-256 9335f61f8ad276d94455c5b6876fea48152c3cea759f2598c8108ee461fa5759 Details →
SHA-256 cd078957167e1af4de39aecdb981cd14156fa81d5a9c6ac51e74ae5b6199a12a Details →
SHA-256 b16e217cdca19e00c1b68bdfb28ead53b20adeabd6edcd91542f9fbf48942877 Details →
SHA-256 d20a3c928761fe00ac522eeb474612b5804cd9108453ea8591106d5d4428428e Details →
SHA-256 8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2 Details →
SHA-256 65ab49119c845801f29a57e8aa177146b2ffbd289d4278109b146f933380f951 Details →
SHA-256 6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4 Details →
SHA-256 252a8bb2eb9c96c5e6cc7cab822e2ed0d508032f9350351221781684e86c03ab Details →
SHA-256 8a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c5531 Details →
SHA-256 e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22 Details →
SHA-256 087f002df0a02c8c74f3ba5cd99cf29fb9efff38bf57b3d808e34a5dd4200dd2 Details →
SHA-256 048e18416177de2ead251abdf4d89837f6807c6aba4d5b1debe49adfdecbf05c Details →
SHA-256 6f9fbe29f8cc2788e2bc9d631e0eea2a8e9837076837b55838005a0e654f0a9e Details →
SHA-256 d0da2832ae1e13a98f7ce7e33a66c1b0d9797b81f69ece134e4462ea55ac923e Details →
SHA-256 ea26980059ef2ad11e99556a4edfa1f8ec769fa9f06aa573b81bedf319954b5 Details →
Domain projetosmecanicos[.]com[.]br Details →
Domain socialbizsolutions[.]com Details →
Domain professionalhomebasedbusiness[.]com Details →
Domain safefire[.]jo Details →
Domain glanz-gmbh[.]de Details →
Domain turnkeyaiagents[.]com Details →
Domain comunidadesparentais[.]com[.]br Details →
Domain mysimerp[.]net Details →
IP 192[.]36[.]27[.]51 Details →
IP 62[.]164[.]177[.]25 Details →
Filename TechSupV18Fix3.zip Details →

MITRE ATT&CK TTPs 41 techniques

T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1053 Scheduled Task/Job · Execution T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1132 Data Encoding · Command And Control T1133 External Remote Services · Persistence T1134 Access Token Manipulation · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1202 Indirect Command Execution · Defense Evasion T1210 Exploitation of Remote Services · Lateral Movement T1222 File and Directory Permissions Modification · Defense Evasion T1484 Domain or Tenant Policy Modification · Defense Evasion T1484.001 Group Policy Modification · Defense Evasion T1486 Data Encrypted for Impact · Impact T1490 Inhibit System Recovery · Impact T1491 Defacement · Impact T1542 Pre-OS Boot · Defense Evasion T1543.002 Systemd Service · Persistence T1543.003 Windows Service · Persistence T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1566 Phishing · Initial Access T1573 Encrypted Channel · Command And Control T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1595 Active Scanning · Reconnaissance T1659 Content Injection · Initial Access