MS Teams Relay Server Ransomware Campaign
MS Teams' adoption of Relay Server was detected on the DragonForce ransomware campaign.
According to a report by the website, Security Week mentioned the reemergence of DragonForce ransomware, which at this time used Microsoft Teams' Relay Server to contact C2 or Command and Control through the use of the system's open back door malware type, or a Backdoor called Backdoor.Turn, a malware created with the Go language with the ability to hide the contact between malware and C2 servers. The malware then steals the token for the user, or the Visitor Token is used with the Relay tool to create the connection. Contact Relay Server with Microsoft TURN and then use the session (Session) QUIC to contact the C2 server and then release DragonForce ransomware on the victim's system. This method, a research team from Symantec, a cybersecurity tool developer, said, is a very deep (Sophisticated) approach.
For the malware, the Backdoor, in addition to its deep capabilities, also provides persistence for hackers to access the victim's system. It is also an intermediary for hackers to run Execute Command, steal passwords saved on the victim's web browser, create a process, scan the victim's network, and perform a LDAP / AD layout, as well as spread ransomware to the connected system (Lateral Movement) with stolen passwords.















































































