DragonForce ransomware deployed Backdoor.Turn, a Go-based backdoor that hides command-and-control traffic inside Microsoft Teams TURN relay infrastructure. The malware obtains an anonymous Teams visitor token and uses legitimate TURN relays during connection setup. Symantec researchers identified this as the first known in-the-wild malware to abuse Teams TURN relays for C2 communications.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
Who Runs the Ransomware Group 'The Gentlemen?'