$ intel.mask2.ca

ADVISORY · 2026-06-16 · SRC BLEEPINGCOMPUTER · HIGH
2026-06-16 high REL 8/10

Ransomware gang hides malicious traffic through Microsoft Teams relay infrastructure

post-secondarygovernmenthealthcarefinancegeneral

A ransomware group known as DragonForce deployed custom malware that leverages Microsoft Teams relay systems to conceal command-and-control communications. This technique exploits legitimate Microsoft infrastructure to evade detection, making it harder for security teams to identify the attack in progress.

Why it matters in Western Canada: Organizations across Western Canada heavily rely on Microsoft 365 and Teams for daily operations. This attack method directly targets enterprises using these ubiquitous platforms, particularly affecting post-secondary institutions, government agencies, and healthcare providers in the region.


Summary generated from the original advisory. Read the full source: bleepingcomputer

Source
https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/
CVEs
None listed
Tags
ransomware, microsoft teams, c2 evasion, backdoor, dragonforce
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)