security-com · Crawled Aug 1, 2026
Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden
33 IoCs 1 Actors
Read original article ↗
AI Summary
The DragonForce ransomware group, tracked by Symantec as Hackledorb, conducted a sophisticated attack against a U.S. services firm, leveraging custom malware and novel techniques to evade detection. The attackers used a Go-based backdoor named Backdoor.Turn, which abuses Microsoft Teams' TURN relay infrastructure to hide command-and-control (C2) traffic behind legitimate Microsoft domains. They also employed DLL sideloading, BYOVD techniques exploiting vulnerable signed drivers—including Huawei’s HWAuidoOs2Ec.sys—and modified system configurations for persistence and lateral movement before deploying the DragonForce ransomware payload.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 33 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 82b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013b | Details → |
| SHA-256 | 821da79d727351dd67ce5df7950e9a3de6647a3cf474bb3a093f67507fed92a6 | Details → |
| SHA-256 | b6628d201c2a68d2a3de2a87de7a5acfe21b101a97928e1c8d5c82102d967383 | Details → |
| SHA-256 | ce66b8221446c9b6d83f0ce6382f430e519601641e5daaaf1ca7a8a8806cb0b0 | Details → |
| SHA-256 | f174c19902523dcf005fa044b6598403a5e5c0a5982398d1bc0dcc5ec1cd351b | Details → |
| SHA-256 | 142bac0e2148e0d47891b6cd7311195c4acbe33b700fad54a201c52a2bc46219 | Details → |
| SHA-256 | 8395b621bb4415090f232c59fc41d24ea41a519b58eabe512f3ae7d2fdf049a3 | Details → |
| SHA-256 | 9335f61f8ad276d94455c5b6876fea48152c3cea759f2598c8108ee461fa5759 | Details → |
| SHA-256 | cd078957167e1af4de39aecdb981cd14156fa81d5a9c6ac51e74ae5b6199a12a | Details → |
| SHA-256 | b16e217cdca19e00c1b68bdfb28ead53b20adeabd6edcd91542f9fbf48942877 | Details → |
| SHA-256 | d20a3c928761fe00ac522eeb474612b5804cd9108453ea8591106d5d4428428e | Details → |
| SHA-256 | 8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2 | Details → |
| SHA-256 | 65ab49119c845801f29a57e8aa177146b2ffbd289d4278109b146f933380f951 | Details → |
| SHA-256 | 6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4 | Details → |
| SHA-256 | 252a8bb2eb9c96c5e6cc7cab822e2ed0d508032f9350351221781684e86c03ab | Details → |
| SHA-256 | 8a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c5531 | Details → |
| SHA-256 | e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22 | Details → |
| SHA-256 | 087f002df0a02c8c74f3ba5cd99cf29fb9efff38bf57b3d808e34a5dd4200dd2 | Details → |
| SHA-256 | 048e18416177de2ead251abdf4d89837f6807c6aba4d5b1debe49adfdecbf05c | Details → |
| SHA-256 | 6f9fbe29f8cc2788e2bc9d631e0eea2a8e9837076837b55838005a0e654f0a9e | Details → |
| SHA-256 | d0da2832ae1e13a98f7ce7e33a66c1b0d9797b81f69ece134e4462ea55ac923e | Details → |
| SHA-256 | ea26980059ef2ad11e99556a4edfa1f8ec769fa9f06aa573b81bedf319954b5 | Details → |
| Domain | projetosmecanicos[.]com[.]br | Details → |
| Domain | socialbizsolutions[.]com | Details → |
| Domain | professionalhomebasedbusiness[.]com | Details → |
| Domain | safefire[.]jo | Details → |
| Domain | glanz-gmbh[.]de | Details → |
| Domain | turnkeyaiagents[.]com | Details → |
| Domain | comunidadesparentais[.]com[.]br | Details → |
| Domain | mysimerp[.]net | Details → |
| IP | 192[.]36[.]27[.]51 | Details → |
| IP | 62[.]164[.]177[.]25 | Details → |
| Filename | TechSupV18Fix3.zip | Details → |
MITRE ATT&CK TTPs 41 techniques
T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1053 Scheduled Task/Job · Execution T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1132 Data Encoding · Command And Control T1133 External Remote Services · Persistence T1134 Access Token Manipulation · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1202 Indirect Command Execution · Defense Evasion T1210 Exploitation of Remote Services · Lateral Movement T1222 File and Directory Permissions Modification · Defense Evasion T1484 Domain or Tenant Policy Modification · Defense Evasion T1484.001 Group Policy Modification · Defense Evasion T1486 Data Encrypted for Impact · Impact T1490 Inhibit System Recovery · Impact T1491 Defacement · Impact T1542 Pre-OS Boot · Defense Evasion T1543.002 Systemd Service · Persistence T1543.003 Windows Service · Persistence T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1566 Phishing · Initial Access T1573 Encrypted Channel · Command And Control T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1595 Active Scanning · Reconnaissance T1659 Content Injection · Initial Access