SUBJECT PROFILE
DragonForce has transitioned from a standard RaaS operation to a highly organized cartel structure with APT-grade tradecraft. A Symantec/Carbon Black report published June 16–17 2026 revealed the group deployed Backdoor.Turn — the first known malware to abuse Microsoft Teams TURN relay infrastructure — to mask C2 traffic as legitimate Teams traffic during a months-long dwell inside a major US services firm. The group also used a then-undocumented BYOVD exploit against a Huawei driver, reflecting substantial investment in offensive tooling.
Financial — evolved cartel-model RaaS with APT-grade custom tooling and persistent post-ransomware access
OPERATIONAL HISTORY
T1190 (Exploit Public-Facing Application – SQL/MSSQL), T1574.002 (DLL Side-Loading), T1553.006 (Bring Your Own Vulnerable Driver – HWAuidoOs2Ec.sys), T1090 (Proxy – TURN relay abuse via MS Teams), T1071 (Application Layer Protocol – QUIC), T1486 (Data Encrypted for Impact), T1003 (Credential Dumping – browser passwords), T1018 (Remote System Discovery – LDAP/AD mapping), T1078 (Valid Accounts), T1543 (Create/Modify System Process – new user accounts)
KNOWN INFRASTRUCTURE
Custom Go-based Backdoor.Turn injected into DbgView64.exe; Microsoft Teams TURN relay as C2 channel (QUIC over legitimate Teams servers); VirtualBox DLL sideload chain; Netscan for reconnaissance; AV killer components; DragonForce ransomware payload (SHA256: e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22)