Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden
Cybercriminal groups continuously adapt to defenders’ detection methods. One of the most concerning trends is the abuse of trusted…
Hidden in Teams: DragonForce Attackers
Weaponize Microsoft Teams Relays to Stay Hidden
Cybercriminal groups continuously adapt to defenders’ detection methods. One of the most concerning trends is the abuse of trusted collaboration platforms. Recent reports indicate that DragonForce-affiliated operators have leveraged Microsoft Teams relays and enterprise communication channels to blend malicious activity into normal business operations. Why Teams?
Security teams often focus on email, endpoints, and network traffic, while collaboration platforms enjoy a higher level of trust. Attackers exploit this trust to communicate, move information, and coordinate activity while remaining hidden in plain sight.
Move information, and coordinate activity while remaining hidden in plain sight.
Key Tactics
• Abuse of legitimate collaboration channels • Social engineering through trusted identities • Living-off-the-land techniques • Stealthy command-and-control communications • Reduced security visibility
Attack Flow
Initial access → Account compromise → Teams abuse → Internal reconnaissance → Lateral movement → Data theft → Extortion or ransomware deployment.

Attack chain
Defensive Recommendations
Implement MFA, monitor Teams activity logs, restrict external access, deploy behavioral analytics, and establish incident response playbooks focused on collaboration platforms.
Conclusion
The DragonForce Teams relay technique highlights a broader cybersecurity reality: trusted platforms can become attack infrastructure. Organizations must expand visibility beyond traditional security boundaries and treat collaboration platforms as critical components of their security monitoring strategy.
메타데이터
- post_id
- b72270935138
- slug
- hidden-in-teams-dragonforce-attackers-weaponize-microsoft-teams-relays-to-stay-hidden-b72270935138
- url
- https://meetcyber.net/hidden-in-teams-dragonforce-attackers-weaponize-microsoft-teams-relays-to-stay-hidden-b72270935138
- canonical_url
- https://meetcyber.net/hidden-in-teams-dragonforce-attackers-weaponize-microsoft-teams-relays-to-stay-hidden-b72270935138
- author_url
- https://medium.com/@ashwinisp
- status
- ok
- fetched_at
- 2026-06-22 12:55:45