DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // DRAGONFORCEFIRST SEEN: JUN 2023

DragonForce

ALSO KNOWN AS: Hackledorb
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (likely Malaysia-origin based on early branding; now operates as an international cartel)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:JUN 2023
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL82/100
RESOURCES82/100
PERSISTENCE85/100
STEALTH77/100
IMPACT91/100

DragonForce has transitioned from a standard RaaS operation to a highly organized cartel structure with APT-grade tradecraft. A Symantec/Carbon Black report published June 16–17 2026 revealed the group deployed Backdoor.Turn — the first known malware to abuse Microsoft Teams TURN relay infrastructure — to mask C2 traffic as legitimate Teams traffic during a months-long dwell inside a major US services firm. The group also used a then-undocumented BYOVD exploit against a Huawei driver, reflecting substantial investment in offensive tooling.

Financial — evolved cartel-model RaaS with APT-grade custom tooling and persistent post-ransomware access

T1190 (Exploit Public-Facing Application – SQL/MSSQL), T1574.002 (DLL Side-Loading), T1553.006 (Bring Your Own Vulnerable Driver – HWAuidoOs2Ec.sys), T1090 (Proxy – TURN relay abuse via MS Teams), T1071 (Application Layer Protocol – QUIC), T1486 (Data Encrypted for Impact), T1003 (Credential Dumping – browser passwords), T1018 (Remote System Discovery – LDAP/AD mapping), T1078 (Valid Accounts), T1543 (Create/Modify System Process – new user accounts)

PROFESSIONAL SERVICES
RETAIL
MANUFACTURING
TECHNOLOGY
FINANCIAL SERVICES

Custom Go-based Backdoor.Turn injected into DbgView64.exe; Microsoft Teams TURN relay as C2 channel (QUIC over legitimate Teams servers); VirtualBox DLL sideload chain; Netscan for reconnaissance; AV killer components; DragonForce ransomware payload (SHA256: e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22)

FILE DATE: DEC 2025
US Services Firm Intrusion (Backdoor.Turn)
DragonForce operators compromised a major unnamed US services firm in December 2025, deploying Backdoor.Turn to hide C2 in Microsoft Teams relay infrastructure and maintaining undetected access for one to two months before deploying ransomware.
FILE DATE: JUN 2026
Backdoor.Turn Public Disclosure
Symantec and Carbon Black published full technical details on June 16–17 ███████████████████ first-ever abuse of TURN relay infrastructure for malware C2 and novel BYOVD exploitation of a Huawei driver.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn