DragonForce operators covertly infiltrated a major U.S. services company and maintained access for up to two months before deploying ransomware, using a Go-based remote access trojan known as Backdoor.Turn to disguise command-and-control traffic as legitimate Microsoft Teams activity. According to reporting from Symantec and others, the malware obtained an anonymous Teams visitor token through Microsoft identity services, leveraged a legitimate Teams TURN relay, and then established a QUIC session to attacker-controlled infrastructure, allowing outbound traffic to blend in with normal collaboration traffic.
The intrusion was reported to have begun with exploitation of an SQL or MSSQL server and progressed through account creation, firewall-rule changes, security-setting modifications, credential theft, lateral movement, and data exfiltration before encryption. Additional reporting on the attack chain described social-engineering and Microsoft Teams-based initial access patterns, while researchers also said the attackers used an undocumented Huawei driver flaw in a BYOVD-style evasion technique to weaken defenses and help reach high-value systems, including domain controller access.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-16, researchers publicly reported their investigation into the 2025 DragonForce intrusion, including the use of Backdoor.Turn to conceal command-and-control traffic within Microsoft Teams TURN relay traffic. The report characterized the operation as exceptionally sophisticated.
In March 2026, Huntress published details about the Huawei driver vulnerability that had been used by the attackers for evasion. The vulnerability had previously been undocumented at the time of the intrusion.
After dwelling in the environment for up to two months, the attackers used DragonForce ransomware to exfiltrate data and encrypt victim systems. The reporting noted no indication of whether the victim paid a ransom.
During the intrusion, the attackers deployed the Go-based Backdoor.Turn RAT, which hid command-and-control traffic inside legitimate Microsoft Teams TURN relay traffic and established QUIC connectivity to attacker infrastructure. They also used an undocumented Huawei driver vulnerability as part of a multi-vector BYOVD evasion approach while changing security settings, creating accounts, and modifying firewall rules to preserve access and move laterally.
In 2025, DragonForce operators infiltrated a major US services firm, likely by exploiting a vulnerability in an SQL or MSSQL server. The attackers maintained access for up to two months before the ransomware stage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcecertego.net
Open sourcesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.