FeedMalwareRansomware gang abuses Microsoft Teams relays to hide malici...
MalwareBleeping Computer
6.5HIGH

Ransomware gang abuses Microsoft Teams relays to hide malicious traffic

📅 16 June 2026 at 10:18 UTC📰 Bleeping ComputerView original source ↗
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic

DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

The DragonForce ransomware gang abused Microsoft Teams relays to hide malicious traffic, using a custom malware named 'Backdoor.Turn' to mask command-and-control communications within the relay infrastructure.

⚙️Technical Details
CVEs
CVE-2023-52271CVE-2025-61155CVE-2025-1055Affected Systems: Windows systems with Topaz Antifraud and GameDriverX64.sys drivers installed
Affected Systems
Windows systems with Topaz Antifraud and GameDriverX64.sys drivers installed
Attack Vectors
LOCALLOW
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Major U.S. services companies, particularly those using Microsoft Teams
🛡️Recommended Actions
1Implement strict controls on Microsoft Teams usage and TURN relay servers
2Regularly update and patch affected systems with Topaz Antifraud and GameDriverX64.sys drivers
3Monitor for suspicious activity related to DragonForce ransomware attacks
📦Affected Products
Topazevolution AntifraudGameDriverX64.sys
🔐NVD Verified DataVERIFIED
CVE-2023-52271CVSS 6.5MEDIUM
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Affected Products (CPE)
Topazevolution Antifraud
CVE-2025-61155CVSS 5.5MEDIUM
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-400
CVE-2025-1055CVSS 5.6MEDIUM
Attack Vector
LOCAL
Complexity
HIGH
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
Weaknesses
CWE-862

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed