In today's ever-evolving digital landscape, we find ourselves grappling with a particularly intriguing and concerning development in the world of cyber threats. The DragonForce hackers, associated with the notorious ransomware group, have demonstrated a remarkable ability to exploit Microsoft Teams' relay infrastructure for their malicious activities. This article delves into the intricacies of this attack, shedding light on the tactics employed and the broader implications it holds for cybersecurity.
The DragonForce Hackers' Innovative Approach
DragonForce, a name that has become synonymous with ransomware, has taken a step further in their quest for stealth and persistence. By utilizing a custom Go-based RAT, Backdoor.Turn, these threat actors have managed to conceal their command-and-control (C2) traffic within Microsoft Teams' relay infrastructure. This innovative approach allows them to operate under the radar, making it challenging for network defenders to detect their presence.
What makes this particularly fascinating is the level of sophistication displayed by DragonForce. They have exploited a vulnerability, potentially in an SQL or MS-SQL server, to gain initial access. This vulnerability, combined with the use of a legitimate Microsoft TURN relay, creates a perfect storm for their malicious activities. The attackers remain on the victim's network for an extended period, up to two months, without raising any red flags.
Unraveling the Attack Timeline
The attack timeline provides a glimpse into the meticulous planning and execution of DragonForce. It all began in December 2025 with a seemingly innocent PowerShell command, which dropped a ZIP archive under the guise of a tech support hotfix. This archive, however, contained a DLL side-loading attack, which then executed a rogue DLL, conducting reconnaissance and setting up persistence on the compromised host.
One aspect that immediately stands out is the use of a Huawei driver, "HWAuidoOs2Ec.sys," as part of the attack. This driver, along with others like "wsftprm.sys," "GameDriverX64.sys," and "K7RKScan.sys," has been employed in various malicious campaigns, including a large-scale malvertising operation targeting tax-related searches. The fact that these drivers are being reused in different contexts highlights the interconnected nature of the cybercriminal underworld.
The Stealthy Nature of Backdoor.Turn
Backdoor.Turn, the custom RAT employed by DragonForce, is a masterpiece of stealth and evasion. It utilizes a technique known as Ghost Calls, documented by Praetorian, to establish a covert communication channel. This mechanism allows the attackers to maintain a persistent presence on the compromised host, even after the deployment of the DragonForce ransomware. The backdoor supports a wide range of capabilities, from command execution to lateral movement, making it a formidable tool in their arsenal.
Implications and the Evolving Threat Landscape
The findings from this attack paint a worrying picture of a highly capable and persistent threat actor. Hackledorb, the group behind DragonForce, has transitioned from a conventional ransomware-as-a-service model to a well-organized cartel structure. Their continuous development of advanced techniques, such as the use of Backdoor.Turn and multi-vector evasion, positions them as one of the most formidable ransomware groups operating today.
As we reflect on this incident, it becomes evident that the cyber threat landscape is constantly evolving. Threat actors are becoming increasingly sophisticated, leveraging legitimate tools and infrastructure to carry out their malicious activities. The case of DragonForce serves as a stark reminder of the need for robust cybersecurity measures and a proactive approach to threat detection and mitigation.
In my opinion, this incident highlights the importance of staying vigilant and adapting to the ever-changing tactics employed by cybercriminals. It is a call to action for organizations and individuals alike to strengthen their cybersecurity posture and remain vigilant against emerging threats.