DragonForce Ransomware Abuses Microsoft Teams TURN Relay to Hide Malicious C2 Traffic
Symantec researchers have discovered that DragonForce ransomware actors used a novel Go-based backdoor called Backdoor.TURN to route C2 communications through Microsoft Teams TURN relay servers — the first real-world exploitation of this technique. The campaign also deployed BYOVD attacks using a Huawei driver and a custom Palo Alto-disguised malicious driver to kill security tools.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.