← Back to list

Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden

Cybercriminal groups continuously adapt to defenders’ detection methods. One of the most concerning trends is the abuse of trusted…

Ashwini Puranik in MeetCyber · 2026-06-16 20:56 · 50 claps · 1.0 min read paywalled
#dragonforce-ransomware #latest-cyber-threats #ransomware #cybersecurity #cyberattack
Open on Medium ↗
Wiki topics: RAG · RAG & Retrieval 🔒 · Cybersecurity

Hidden in Teams: DragonForce Attackers

Weaponize Microsoft Teams Relays to Stay Hidden

Cybercriminal groups continuously adapt to defenders’ detection methods. One of the most concerning trends is the abuse of trusted collaboration platforms. Recent reports indicate that DragonForce-affiliated operators have leveraged Microsoft Teams relays and enterprise communication channels to blend malicious activity into normal business operations. Why Teams?

Security teams often focus on email, endpoints, and network traffic, while collaboration platforms enjoy a higher level of trust. Attackers exploit this trust to communicate, move information, and coordinate activity while remaining hidden in plain sight.

Move information, and coordinate activity while remaining hidden in plain sight.

Key Tactics

• Abuse of legitimate collaboration channels • Social engineering through trusted identities • Living-off-the-land techniques • Stealthy command-and-control communications • Reduced security visibility

Attack Flow

Initial access → Account compromise → Teams abuse → Internal reconnaissance → Lateral movement → Data theft → Extortion or ransomware deployment.

Attack chain

Attack chain

Defensive Recommendations

Implement MFA, monitor Teams activity logs, restrict external access, deploy behavioral analytics, and establish incident response playbooks focused on collaboration platforms.

Conclusion

The DragonForce Teams relay technique highlights a broader cybersecurity reality: trusted platforms can become attack infrastructure. Organizations must expand visibility beyond traditional security boundaries and treat collaboration platforms as critical components of their security monitoring strategy.


메타데이터
post_id
b72270935138
slug
hidden-in-teams-dragonforce-attackers-weaponize-microsoft-teams-relays-to-stay-hidden-b72270935138
url
https://meetcyber.net/hidden-in-teams-dragonforce-attackers-weaponize-microsoft-teams-relays-to-stay-hidden-b72270935138
canonical_url
https://meetcyber.net/hidden-in-teams-dragonforce-attackers-weaponize-microsoft-teams-relays-to-stay-hidden-b72270935138
author_url
https://medium.com/@ashwinisp
status
ok
fetched_at
2026-06-22 12:55:45