<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Dragonforce on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/dragonforce/</link><description>Recent content in Dragonforce on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 18 Jun 2025 13:30:07 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/dragonforce/index.xml" rel="self" type="application/rss+xml"/><item><title>DragonForce Abuses Microsoft Teams C2 Traffic</title><link>https://zxcloudsecurity.co.uk/posts/dragonforce-ransomware-microsoft-teams-relay-backdoor-turn-c2/</link><pubDate>Thu, 18 Jun 2026 13:30:07 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/dragonforce-ransomware-microsoft-teams-relay-backdoor-turn-c2/</guid><description>DragonForce ransomware uses a Go-based RAT to hide C2 traffic inside Microsoft Teams relay infrastructure, evading detection on enterprise networks.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/dragonforce-hackers-abuse-microsoft.html">The Hacker News</a></p>
<hr>
<p>The DragonForce ransomware group has deployed a custom Go-based backdoor, Backdoor.Turn, that tunnels command-and-control traffic through Microsoft Teams relay infrastructure to evade detection. By blending malicious traffic with legitimate Teams communications, the group makes it significantly harder for defenders to identify or block C2 activity. The technique was observed in an attack against a major US services organisation, flagged by Symantec and Carbon Black.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review your Microsoft Teams egress traffic and ensure your CASB or network monitoring tools can inspect and baseline Teams relay communications — legitimate use should never involve unusual outbound patterns or unexpected relay endpoints. Consider implementing Zero Trust network segmentation so that even if a host is compromised, lateral movement and C2 exfiltration via trusted SaaS channels is detected and restricted.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/dragonforce-hackers-abuse-microsoft.html">DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic</a></p>
]]></content:encoded></item></channel></rss>