Find notable cyber news and cases, enriched with sources, timelines, and signals.

Major U.S. services company hit by ransomware attack linked to DragonForce

Incident
First reported
Last updated
Happening score
H score 38
3 unique sources, 3 articles

Summary

Hide ▲

A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and-control traffic in Microsoft Teams relay infrastructure. Researchers said the intrusion used a Go-based RAT, Backdoor.Turn, to blend outbound activity into legitimate Microsoft Teams and TURN relay connections before establishing a direct QUIC session to attacker infrastructure. The campaign also used DLL sideloading, BYOVD evasion, and process injection into DbgView64.exe after ransomware deployment, while the suspected initial access came through an SQL or MS-SQL server flaw or an initial access broker.

Related Happenings

GodDamn ransomware PoisonX BYOVD activity

Malware Activity
H score14 First: 09.07.2026 13:43 Last: 09.07.2026 13:43 Sources 1

About this happening: GodDamn ransomware, part of the Hyadina family, has evolved into a Windows intrusion chain that uses AnyDesk, credential theft, and the PoisonX kernel driver t...

Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave

Exploitation Wave
H score41 First: 30.06.2026 11:53 Last: 30.06.2026 11:53 Sources 1

About this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...

Klue hit by network compromise

Incident
H score39 First: 18.06.2026 17:19 Last: 18.06.2026 17:19 Sources 1

About this happening: Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastru...

Latest development: 23.06.2026 16:58

Unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in LastPass's Salesforce environment. LastPass said its products, services, infrastructure, and customer vaults were not affected, and it disabled employee access to Klue, rotated exposed API/OAuth tokens, and notified law enforcement.

DragonForce / Hackledorb pivots from RaaS to a formalized cartel structure

Threat Actor Meta
H score26 First: 18.06.2026 16:30 Last: 18.06.2026 16:30 Sources 1

How related: This is particularly significant as Hackledorb, the threat actor behind DragonForce, has pivoted from a conventional ransomware-as-a-service (RaaS) model to a highly organized, formalized cartel structure.

About this happening: Hackledorb has pivoted DragonForce from a conventional ransomware-as-a-service (RaaS) model into a formalized cartel structure, signaling a more organized and dura...

Backdoor.Turn Microsoft Teams TURN relay malware activity

Malware Activity
H score29 First: 16.06.2026 13:18 Last: 16.06.2026 13:18 Sources 1

How related: The cybercriminals used a Go-based Remote Access Trojan (RAT) to abuse Microsoft Teams' TURN relay servers and mask command-and-control traffic.

About this happening: Backdoor.Turn is a Go-based RAT tied to DragonForce ransomware operators that hid command-and-control traffic through Microsoft Teams TURN relay infrastructure dur...

Timeline

  1. 16.06.2026 13:18 4 articles · 29d ago

    Major U.S. services company hit by ransomware attack linked to DragonForce

    Initial Disclosure

    In December 2025, the intrusion likely started with exploitation of an unknown SQL or MSSQL server flaw. The attacker then established foothold and built persistence before moving into evasion and ransomware deployment.

    Show sources