DragonForce Evolves: Teams-Relayed C2 and BYOVD Kernel Evasion
The DragonForce ransomware cartel debuted Backdoor.Turn, a Go-based backdoor that hides C2 inside legitimate Microsoft Teams TURN-relay traffic, alongside multi-vector BYOVD driver abuse for kernel-level defense evasion.
TA2026284Published September 25, 2026Admiralty A1TA2026284A13 signed vulnerable driversSummary
DragonForce has evolved into a mature ransomware cartel, rebranding in March 2025 to let affiliates operate under their own brands on its LockBit/Conti-based infrastructure. In a late-2025 intrusion it debuted Backdoor.Turn, a Go-based backdoor that hides C2 inside legitimate Microsoft Teams TURN-relay traffic, the first known in-the-wild abuse of its kind, alongside multi-vector BYOVD driver exploitation for kernel-level defense evasion.
The DragonForce Windows locker uses ChaCha8 encryption with RSA-4096 key wrapping and network-aware SMB-share encryption, marking a clear shift toward stealthy, high-impact targeted campaigns.
Malware
Targeted Platform
Targeted Regions (51)
Taiwan, United States, France, United Kingdom, Dominican Republic, Portugal, Argentina, Brazil, Haiti, South Korea, China, Thailand, Germany, Colombia, Egypt, Canada, Botswana, Bahrain, South Africa, Switzerland, United Arab Emirates, India, Italy, Philippines, Ecuador, Saudi Arabia, Australia, Chile, Pakistan, Japan, Turkey, Sweden, Lebanon, Mexico, Sri Lanka, Peru, Netherlands, Israel, Spain, Austria, Singapore, Isle of Man, Greece, Norway, Vietnam, Guatemala, Slovakia, Iran, Costa Rica, Bulgaria, Venezuela
Targeted Industries (26)
Aerospace, Defense, Agriculture, Associations, Aviation, Business Services & Consulting, Casino & Gambling, Charitable Organizations, Education, Energy, Financial Services, Food Service, Government, Healthcare, Hospitality, Insurance, Legal, Manufacturing, Media, Pharmaceutical, Real Estate, Religion, Retail, Technology, Telecommunications, Transportation
Attack Details
- #01
DragonForce has matured from a conventional ransomware brand into one of the most capable and organizationally mature operations active today. Its payloads are built on leaked LockBit
3.0and Conti code, and a RaaS program formalized in mid-2024 offered affiliates up to80%of ransom proceeds. OnMarch 19, 2025, it rebranded as the "DragonForce Ransomware Cartel," letting affiliates operate under their own brands using its infrastructure and tools. Within24hours it defaced the BlackLock and Mamona leak sites, and it subsequently absorbed RansomHub's orphaned affiliates. - #02
The most significant technical upgrade appeared in an intrusion against a major U.S. services firm, where operators gained access in December 2025 and remained for one to two months. They deployed Backdoor.Turn, a custom Go-based backdoor that obtains an anonymous Teams visitor token through Skype-backed identity services, sets up its connection via a legitimate Microsoft TURN relay, then runs a QUIC session to the real C2, so defenders see only outbound traffic to genuine Teams servers. This is the first known in-the-wild abuse of TURN relays for this purpose.
- #03
Defense evasion advanced through multi-vector BYOVD abuse combining three signed vulnerable drivers (
CVE-2023-52271,CVE-2025-61155,CVE-2025-1055) with a novel "Havoc Process Terminator" technique exploiting Huawei'sHWAuidoOs2Ec.sys, a driver not previously known to be exploited in the wild. Separately, they used a custom malicious driver masquerading as a Palo Alto component. The goal throughout was kernel access to terminate security processes. - #04
The DragonForce Windows locker pairs per-file ChaCha8 encryption with RSA-4096 key wrapping and appends a fixed
537-byte metadata footer. It scans private IP ranges andTCP/445, then encrypts reachable SMB shares under the current token, skipping only theADMIN$share. Together, these upgrades, stealthy C2, novel driver abuse, and a cartel-style affiliate model, mark a deliberate move toward high-impact, resource-heavy, targeted campaigns.
CVEs
| CVE | Name | Affected Product | Zero-Day | CISA KEV | Patch |
|---|---|---|---|---|---|
CVE-2023-52271 | Topaz Antifraud Improper Access Control Vulnerability | Topaz Antifraud (wsftprm.sys driver) | No | No | Available |
CVE-2025-61155 | Hotta Studio GameDriver X64 Improper Access Control Vulnerability | Tower of Fantasy (Gamedriverx64.sys driver) | No | No | Unavailable |
CVE-2025-1055 | K7 Computing K7 Security Anti-Malware Missing Authorization Vulnerability | K7 Security (K7RKScan.sys driver) | No | No | Available |
Recommendations
- 01Restrict and Monitor SMB Reach
Immediately segment storage networks, minimize writable share access, and monitor for
TCP/445fan-out,NetShareEnumenumeration, and bulk remote writes, since a single privileged token can encrypt many reachable shares even without worm-like propagation. - 02Hunt for .df_win and the Fixed Footer
Deploy detection for files renamed with the
.df_winextension and for the deterministic537-byte recovery footer appended to encrypted files, both of which are durable artifacts independent of builder-configured indicators. - 03Block Known Command-and-Control Infrastructure
Block the identified downloader command-and-control domains, the Backdoor.Turn C&C IP, and the malicious archive download URL at the network perimeter, and hunt historical logs for connections to them.
- 04Enforce Vulnerable Driver Blocklisting
Enable Microsoft's vulnerable-driver blocklist and application-control policies to prevent loading of the abused signed drivers (
wsftprm.sys,Gamedriverx64.sys,K7RKScan.sys,HWAuidoOs2Ec.sys) and the impersonating Palo Alto driver used for kernel-level defense evasion. - 05Protect Shadow Copies and Recovery Paths
Monitor WMI and WMIC calls that enumerate and delete
Win32_ShadowCopyobjects, restrict the accounts able to remove volume shadow copies, and maintain offline, immutable backups outside the reach of the current security token. - 06Harden Internet-Facing Database Servers
Prioritize patching, credential hygiene, and exposure reduction for SQL and MSSQL servers, the assessed initial-access surface, and place them behind restrictive network controls.
- 07Inspect Anomalous Microsoft Teams Traffic
Because the backdoor hides command-and-control inside legitimate Teams TURN-relay traffic, baseline expected Teams connectivity and investigate anonymous Teams visitor-token requests or QUIC sessions that do not correspond to genuine user conferencing activity.
- 08Maintain Offline, Tested Backups
Keep immutable or offline backups and rehearse restoration, since the DragonForce operation still threatens encryption under its double-extortion model.
Indicators of Compromise (IoCs)
| Type | Value |
|---|---|
SHA256 | 82b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013b |
SHA1 | 55acb53f348c9f6b89343dc8d96522aa75e4cfdb |
MD5 | bd47ae24b03e5ba0f1ab2e95e7acb989 |
Domains | projetosmecanicos[.]com[.]br |
IPv4 | 62[.]164[.]177[.]25 |
URL | hxxp[:]//192[.]36[.]27[.]51/TechSupV18Fix3[.]zip |
Filename | vboxrt.dll |
File Path | C:\Users\Public\log.log |
Mutex | hsfjuukjzloqu28oajh727190 |
Tox ID | 1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20 |
TOR Address | 3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd[.]onion |
MITRE ATT&CK TTPs
T1190T1078T1047T1059T1059.003T1136T1053T1053.005T1068T1574T1574.002T1562T1562.001T1562.004T1027T1112T1555T1555.003T1003T1046T1135T1018T1087T1087.002T1021T1090T1102T1071T1048T1486T1490T1489References & Patch Links
Patch Details
CVE-2023-52271Topaz Antifraud (wsftprm.sys) - Fixed in version above2.0.0.0.CVE-2025-1055K7 Security Anti-Malware (K7RKScan.sys) - Fixed in version23.0.0.10or later.
Recent Breaches (20)
https://www.hec-group.com.twhttps://www.arizonavascular.comhttps://www.pjemetal.comhttps://www.polyresine.comhttps://www.communitypropertymanagement.comhttps://www.owenleighoptometry.co.ukhttps://www.medicaldepartmentstore.comhttps://www.norwoodlegal.comhttps://www.homewoodsales.comhttps://www.arsrenacer.comhttps://www.frato.comhttps://www.winfashion.comhttps://www.brookviewfinancial.comhttps://www.wozair.comhttps://www.criba.com.arhttps://www.hoganomidi.comhttps://www.rdmachine.comhttps://www.vermont.com.brhttps://www.rubbermill.comhttps://www.gbgroup.com
