
DragonForce ransomware operators targeted a major US services company in December 2025, deploying a custom backdoor called Backdoor.Turn. The malware abuses Microsoft Teams TURN relays to blend command-and-control traffic with legitimate Teams communications, marking the first in-the-wild use of the Ghost Calls technique.
Tap to vote and see what everyone thinks.
Summary by ByteBrief