Major U.S. services company hit by ransomware attack linked to DragonForce
Incident
Summary
Hide ▲
Show ▼
A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and-control traffic in Microsoft Teams relay infrastructure. Researchers said the intrusion used a Go-based RAT, Backdoor.Turn, to blend outbound activity into legitimate Microsoft Teams and TURN relay connections before establishing a direct QUIC session to attacker infrastructure. The campaign also used DLL sideloading, BYOVD evasion, and process injection into DbgView64.exe after ransomware deployment, while the suspected initial access came through an SQL or MS-SQL server flaw or an initial access broker.
Related Happenings
GodDamn ransomware PoisonX BYOVD activity
Malware Activity
H score14
First: 09.07.2026 13:43
Last: 09.07.2026 13:43
Sources 1
About this happening:
GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
GodDamn ransomware PoisonX BYOVD activity
Malware ActivityAbout this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation Wave
H score41
First: 30.06.2026 11:53
Last: 30.06.2026 11:53
Sources 1
About this happening:
CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation WaveAbout this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Klue hit by network compromise
Incident
H score39
First: 18.06.2026 17:19
Last: 18.06.2026 17:19
Sources 1
About this happening:
Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastru...
Klue hit by network compromise
IncidentAbout this happening: Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastru...
Latest development: 23.06.2026 16:58
Unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in LastPass's Salesforce environment. LastPass said its products, services, infrastructure, and customer vaults were not affected, and it disabled employee access to Klue, rotated exposed API/OAuth tokens, and notified law enforcement.
DragonForce / Hackledorb pivots from RaaS to a formalized cartel structure
Threat Actor Meta
H score26
First: 18.06.2026 16:30
Last: 18.06.2026 16:30
Sources 1
How related:
This is particularly significant as Hackledorb, the threat actor behind DragonForce, has pivoted from a conventional ransomware-as-a-service (RaaS) model to a highly organized, formalized cartel structure.
About this happening:
Hackledorb has pivoted DragonForce from a conventional ransomware-as-a-service (RaaS) model into a formalized cartel structure, signaling a more organized and dura...
DragonForce / Hackledorb pivots from RaaS to a formalized cartel structure
Threat Actor MetaHow related: This is particularly significant as Hackledorb, the threat actor behind DragonForce, has pivoted from a conventional ransomware-as-a-service (RaaS) model to a highly organized, formalized cartel structure.
About this happening: Hackledorb has pivoted DragonForce from a conventional ransomware-as-a-service (RaaS) model into a formalized cartel structure, signaling a more organized and dura...
Backdoor.Turn Microsoft Teams TURN relay malware activity
Malware Activity
H score29
First: 16.06.2026 13:18
Last: 16.06.2026 13:18
Sources 1
How related:
The cybercriminals used a Go-based Remote Access Trojan (RAT) to abuse Microsoft Teams' TURN relay servers and mask command-and-control traffic.
About this happening:
Backdoor.Turn is a Go-based RAT tied to DragonForce ransomware operators that hid command-and-control traffic through Microsoft Teams TURN relay infrastructure dur...
Backdoor.Turn Microsoft Teams TURN relay malware activity
Malware ActivityHow related: The cybercriminals used a Go-based Remote Access Trojan (RAT) to abuse Microsoft Teams' TURN relay servers and mask command-and-control traffic.
About this happening: Backdoor.Turn is a Go-based RAT tied to DragonForce ransomware operators that hid command-and-control traffic through Microsoft Teams TURN relay infrastructure dur...
Timeline
-
16.06.2026 13:18 4 articles · 29d ago
Major U.S. services company hit by ransomware attack linked to DragonForce
Initial DisclosureIn December 2025, the intrusion likely started with exploitation of an unknown SQL or MSSQL server flaw. The attacker then established foothold and built persistence before moving into evasion and ransomware deployment.
Show sources
- Ransomware gang abuses Microsoft Teams relays to hide malicious traffic — www.bleepingcomputer.com — 16.06.2026 13:18
- Ransomware gang abuses Microsoft Teams relays to hide malicious traffic — www.bleepingcomputer.com — 16.06.2026 13:18
- DragonForce Ransomware Exploited Microsoft Teams to Hide in Attack Against Major Company — www.infosecurity-magazine.com — 16.06.2026 14:30
- DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic — thehackernews.com — 18.06.2026 16:30