In the ever-evolving landscape of cyber threats, the DragonForce hacking group has demonstrated a particularly cunning and sophisticated approach. Their recent abuse of Microsoft Teams' relay infrastructure to hide backdoor traffic is a prime example of how threat actors are pushing the boundaries of evasion techniques.
What makes this particularly fascinating is the group's use of a custom Go-based RAT, Backdoor.Turn, to exploit vulnerabilities and maintain persistent access to compromised networks. Personally, I think this level of customization and innovation showcases a highly skilled and adaptive adversary.
The attack, which targeted a major U.S. services firm, involved obtaining an anonymous Teams visitor token and leveraging Microsoft's TURN relay to establish a connection with the attacker's C2 server. From my perspective, this abuse of a legitimate service to conceal malicious activity is a worrying trend, as it can make detection and mitigation significantly more challenging for network defenders.
Uncovering the Attack
According to Symantec and Carbon Black, the attackers gained initial access through an SQL or MS-SQL server vulnerability or potentially via an initial access broker. This initial foothold allowed them to execute a series of malicious activities, including a DLL side-loading attack and the use of a Huawei driver to silence security software.
One detail that I find especially interesting is the timing of the attack. The initial malicious activity began in December 2025, suggesting a well-planned and coordinated operation. The attackers took their time, remaining on the victim's network for up to two months, which highlights their patience and persistence.
The Role of BYOVD
The DragonForce group employed a technique known as Bring Your Own Vulnerable Driver (BYOVD), which involves using custom-built malicious drivers to evade detection. This technique was previously observed in Medusa ransomware attacks and has now been leveraged by DragonForce in a large-scale malvertising campaign targeting U.S. tax-related searches.
What this really suggests is that threat actors are sharing and building upon each other's tactics, creating a sort of underground knowledge base. It's a worrying development, as it indicates a community of hackers continuously learning and improving their methods.
Ghost Calls and Stealthy Communication
Backdoor.Turn's underlying mechanism relies on a stealthy C2 communication technique called Ghost Calls, documented by Praetorian. This technique allows the backdoor to establish a direct QUIC session to the C&C server, making it difficult for defenders to detect and block the communication.
In my opinion, the use of Ghost Calls is a clever tactic that showcases the group's understanding of network protocols and their ability to exploit them for their gain. It's a reminder that threat actors are constantly evolving their methods to stay one step ahead.
The DragonForce Evolution
The findings paint a picture of a highly capable and persistent threat actor. DragonForce, formerly operating as a conventional RaaS group, has evolved into a structured cartel, adopting advanced techniques and continuously developing their capabilities.
What many people don't realize is that the shift from RaaS to a more organized structure indicates a higher level of sophistication and a potential move towards more targeted and lucrative attacks. It's a worrying development, as it suggests that these groups are becoming more professional and efficient in their operations.
Conclusion
The DragonForce hacking group's abuse of Microsoft Teams' relay infrastructure is a stark reminder of the evolving nature of cyber threats. Their use of custom tools, advanced evasion techniques, and persistent access strategies highlights the need for constant vigilance and adaptation in the cybersecurity landscape. As threat actors continue to innovate, it's crucial for defenders to stay ahead of the curve and develop equally sophisticated detection and mitigation strategies.