Actor Profile

DragonForce is a threat actor associated with ransomware operations. The group has demonstrated advanced capabilities in developing custom tooling and leveraging legitimate cloud infrastructure for command-and-control communications. DragonForce's deployment of a bespoke Go-based remote access trojan (Backdoor.Turn) indicates a focus on operational security and evasion, utilizing Microsoft Teams relay infrastructure to obscure malicious traffic. The actor's motivation appears to be financially driven, consistent with ransomware-as-a-service or extortion-based operations targeting high-value organizations in the services sector.

TTPs (Tactics, Techniques, Procedures)

DragonForce employs custom malware development (Backdoor.Turn, a Go-based RAT) for remote access and persistence. The group leverages living-off-the-land techniques by abusing Microsoft Teams relay infrastructure for command-and-control communications (T1071.001 - Application Layer Protocol: Web Protocols), enabling traffic to blend with legitimate enterprise communications. This infrastructure abuse technique provides significant evasion capabilities against network-based detection. The deployment of custom backdoors prior to ransomware execution suggests a multi-stage attack methodology involving initial access, reconnaissance, and lateral movement before final payload deployment (T1219 - Remote Access Software, T1105 - Ingress Tool Transfer).

Targets & Patterns

DragonForce has targeted the U.S. services sector, specifically a major services firm according to Symantec and Carbon Black reporting. The selection of a high-profile services organization suggests the actor prioritizes targets with significant revenue potential for extortion demands. Services sector organizations often handle sensitive client data and face substantial operational disruption costs, making them attractive ransomware targets. The deployment of sophisticated custom tooling against this victim indicates DragonForce invests resources in high-value targets rather than opportunistic mass exploitation. Geographic focus on the United States aligns with broader ransomware trends targeting Western economies with greater ability to pay ransom demands.

Historical Context

This activity represents documented use of Backdoor.Turn by DragonForce, as reported by Symantec and Carbon Black researchers. The abuse of Microsoft Teams infrastructure for C2 communications reflects an emerging trend among threat actors to leverage trusted cloud platforms (previously observed with Slack, Discord, and other collaboration tools) for evasion. DragonForce's use of custom Go-based malware aligns with industry-wide adoption of Go for cross-platform malware development due to its portability and obfuscation characteristics. The specific relationship between this campaign and previous DragonForce ransomware operations requires further correlation, though the deployment of custom backdoors prior to encryption is consistent with modern ransomware operational models emphasizing data exfiltration and double-extortion tactics.

Defensive Recommendations

  • Monitor and baseline Microsoft Teams traffic patterns; investigate anomalous relay connections, unusual data volumes, or connections from non-standard endpoints that may indicate C2 abuse (T1071.001)
  • Implement application-aware firewall rules and conditional access policies to restrict Microsoft Teams usage to authorized clients and enforce multi-factor authentication for all cloud collaboration platforms
  • Deploy behavioral detection for Go-based executables, particularly those exhibiting network communication patterns inconsistent with legitimate business applications; hunt for unsigned or recently compiled Go binaries
  • Enable enhanced logging for cloud collaboration platforms including Teams, capturing connection metadata, file transfers, and external relay usage for forensic analysis
  • Conduct threat hunting for Backdoor.Turn indicators of compromise provided by Symantec/Carbon Black, including file hashes, network signatures, and behavioral patterns associated with the RAT

---

# Geopolitical Context

Geopolitical Context

The deployment of Backdoor.Turn by DragonForce ransomware operators represents an evolution in adversary tradecraft, leveraging legitimate enterprise collaboration platforms to evade detection. By tunneling command-and-control traffic through Microsoft Teams relay infrastructure, the threat actors demonstrate sophisticated understanding of corporate network environments and defensive blind spots. This technique complicates attribution and network monitoring, as Teams traffic is typically trusted and encrypted. The targeting of a major U.S. services firm suggests either financially motivated cybercrime or potential dual-use capabilities that could serve strategic intelligence objectives. The use of custom Go-based tooling indicates sustained development resources and operational maturity beyond typical ransomware-as-a-service models.

State Actor Alignment

DragonForce has not been publicly attributed to any state-sponsored actor by U.S. or allied government agencies. The group appears to operate as a financially motivated cybercriminal entity. However, the sophistication of custom tooling and infrastructure abuse techniques may indicate access to advanced development capabilities. No current sanctions designations or formal government attributions are associated with this actor. The targeting of U.S. critical services infrastructure aligns with patterns observed in both criminal and state-nexus operations, though motive remains unclear. U.S. authorities, including CISA and FBI, have not issued formal advisories linking DragonForce to nation-state activity as of available reporting.

Business Impacty pro region

The compromise of a major U.S. services firm carries potential cascading effects for supply chain partners and clients across North America and allied economies. If the targeted entity provides business-critical services to government or defense industrial base customers, the incident may have broader national security implications. European organizations using similar Microsoft 365 and Teams deployments face comparable exposure to this evasion technique. The abuse of trusted collaboration platforms undermines confidence in cloud-based enterprise tools and may prompt regulatory scrutiny from the European Commission and national data protection authorities. For NATO allies, the incident underscores the need for enhanced monitoring of legitimate administrative channels and encrypted collaboration traffic, particularly in sectors supporting critical infrastructure or defense operations.

Forecast

If DragonForce continues to refine techniques for abusing trusted enterprise platforms, other ransomware and intrusion groups are likely to adopt similar methods, increasing the difficulty of network-based threat detection. Should the targeted U.S. services firm experience operational disruption or data exfiltration, downstream impacts on clients and partners may emerge over the coming weeks. If U.S. or allied intelligence agencies identify state-nexus ties to DragonForce operations, the group may face sanctions designations or public attribution, though no evidence currently supports such linkage. Enterprises relying on Microsoft Teams and similar platforms should anticipate increased scrutiny of outbound collaboration traffic and may implement additional monitoring controls in response to this tradecraft evolution.