Ransomware gang hides malicious traffic through Microsoft Teams relay infrastructure
post-secondarygovernmenthealthcarefinancegeneral
A ransomware group known as DragonForce deployed custom malware that leverages Microsoft Teams relay systems to conceal command-and-control communications. This technique exploits legitimate Microsoft infrastructure to evade detection, making it harder for security teams to identify the attack in progress.
Why it matters in Western Canada: Organizations across Western Canada heavily rely on Microsoft 365 and Teams for daily operations. This attack method directly targets enterprises using these ubiquitous platforms, particularly affecting post-secondary institutions, government agencies, and healthcare providers in the region.
Summary generated from the original advisory. Read the full source: bleepingcomputer
- Source
- https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/
- CVEs
- None listed
- Tags
- ransomware, microsoft teams, c2 evasion, backdoor, dragonforce
- Provenance
- mask2-ti-pipeline (AI-assisted, human-reviewable)