DragonForce Hackers Abuse Microsoft Teams Relays to Hide BackdoorTurn C2 Traffic

Threat actors associated with the DragonForce ransomware have been observed using a custom Gobased remote access trojan RAT called BackdoorTurn to conceal commandandcontrol C2 traffic inside Microsoft Teams relay infrastructure According to findings from Broadcomowned Symantec and Carbon Black the backdoor was deployed against a major US services firm The name of the company was