Microsoft Teams users beware — relays hit by ransomware hackers looking to hide malicious traffic



  • Symantec confirms DragonForce ransomware operators used Microsoft Teams TURN relays for covert C2 traffic
  • Custom Go‑based RAT “Backdoor.Turn” masked malicious activity as normal Teams communications
  • First in‑the‑wild use of “Ghost Calls” technique; campaign shows highly sophisticated tradecraft with Scattered Spider links

Experts have warned cybercriminals are using Microsoft Teams relays as command-and-control (C2) infrastructure, blending malicious traffic with benign corporate communications.

In Microsoft Teams, a relay is a server that helps carry audio and video traffic when a direct connection between participants isn’t possible (for example, they’re on a corporate network or behind a firewall).

https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img