COMPAMIR
High-Purity Fact Pipeline
High-Purity Fact Pipeline
DragonForce ransomware group, Symantec
USA
June 2026
Verified: June 16, 2026
"DragonForce ransomware operators disguised command-and-control traffic as legitimate Microsoft Teams activity. A custom Go-based backdoor named 'Backdoor.Turn' was used to facilitate this. This technique allows attackers to bypass security monitoring by blending into trusted corporate traffic."
Author: Andy Greenberg
This book provides a deep dive into the evolution of sophisticated state-sponsored and criminal cyber operations, illustrating how attackers bypass traditional defenses by exploiting trusted infrastructure and supply chains, which is highly relevant to the DragonForce tactic of abusing legitimate platforms like Microsoft Teams.
As an Amazon Associate, COMPAMIR earns from qualifying purchases.