Home / Jun 17, 2026 / Story
0
#8 BleepingComputer general June 16, 2026 at 10:18 UTC

Ransomware gang abuses Microsoft Teams relays to hide malicious traffic

By Bill Toulas

AI Summary

DragonForce ransomware group deployed a custom malware named 'Backdoor.Turn' that tunnels C2 traffic through Microsoft Teams relay infrastructure, effectively masking malicious communications within legitimate enterprise traffic. This technique complicates network-based detection since traffic originates from trusted Microsoft IP ranges used by Teams.

Relevance score: 78.0/100

# More from June 17