MalwareBleeping Computer
6.5 — HIGH
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
The DragonForce ransomware gang abused Microsoft Teams relays to hide malicious traffic, using a custom malware named 'Backdoor.Turn' to mask command-and-control communications within the relay infrastructure.
⚙️Technical Details
CVEs
CVE-2023-52271CVE-2025-61155CVE-2025-1055Affected Systems: Windows systems with Topaz Antifraud and GameDriverX64.sys drivers installed
Affected Systems
Windows systems with Topaz Antifraud and GameDriverX64.sys drivers installed
Attack Vectors
LOCALLOW
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Major U.S. services companies, particularly those using Microsoft Teams
🛡️Recommended Actions
1Implement strict controls on Microsoft Teams usage and TURN relay servers
2Regularly update and patch affected systems with Topaz Antifraud and GameDriverX64.sys drivers
3Monitor for suspicious activity related to DragonForce ransomware attacks
📦Affected Products
Topazevolution AntifraudGameDriverX64.sys
🔐NVD Verified DataVERIFIED
CVE-2023-52271 ↗CVSS 6.5 — MEDIUM
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HAffected Products (CPE)
Topazevolution Antifraud
CVE-2025-61155 ↗CVSS 5.5 — MEDIUM
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HWeaknesses
CWE-400
CVE-2025-1055 ↗CVSS 5.6 — MEDIUM
Attack Vector
LOCAL
Complexity
HIGH
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:HWeaknesses
CWE-862
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
