Skip to main content
    Ransomware Gangs Are Hiding Inside Microsoft Teams at Work
    Cybersecurity
    Important
    3 min read

    Ransomware Gangs Are Hiding Inside Microsoft Teams at Work

    Cybercriminals are disguising their attacks as normal Microsoft Teams traffic, making it harder for businesses to detect threats before it's too late.

    Source

    GetCyberRight Intelligence

    Original headline: Ransomware Hides Inside Microsoft Teams Traffic

    Plain-English summary by GetCyberRight. Read the full report at the source above.

    Published Tuesday, June 16, 20263 min read
    Share:

    What's Happening

    Cybercriminals from the DragonForce ransomware group have found a clever way to sneak past security systems. They're hiding their malicious activity inside Microsoft Teams traffic, the same communication tool millions of workers use every day. This matters because security teams typically trust Teams traffic, making these attacks much harder to spot before damage occurs.

    The Details

    Here's how this works in plain terms. When you use Microsoft Teams at work, your messages travel through Microsoft's relay infrastructure. This is the digital pathway that carries your video calls, chats, and file shares. Hackers have created custom malware called Backdoor.Turn that disguises itself as normal Teams communication.

    Think of it like a burglar wearing a delivery uniform to blend in with legitimate visitors. Security systems see what looks like regular Microsoft Teams traffic and let it pass through. Meanwhile, the malware is quietly establishing a connection that allows attackers to control infected computers and eventually deploy ransomware.

    This technique is particularly dangerous because most companies configure their firewalls to allow Teams traffic without scrutiny. After all, blocking it would prevent employees from doing their jobs. DragonForce is exploiting this trust to hide in plain sight.

    Who Is Affected

    This threat primarily impacts professionals who work at organizations using Microsoft Teams. If your workplace relies on Teams for daily communication, your company's network could be vulnerable. IT departments and security teams need to pay close attention to this development.

    However, families should care too. If a parent's work computer gets infected, attackers might access personal information stored on that device. Some people use work computers for personal tasks, which could expose family photos, passwords, or financial documents. The line between work and home security is thinner than most people realize.

    What You Should Do Right Now

    1. Keep work and personal activities completely separate. Never log into personal email, banking, or social media accounts on your work computer. Use your personal devices for personal matters.

    Stay one step ahead of scammers

    Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.

  1. Enable multi-factor authentication everywhere possible. This includes your Microsoft 365 account, company VPN, and any work applications. It adds a critical second layer of protection if passwords get stolen.

  2. Report suspicious Teams messages immediately. If you receive unexpected files, links, or meeting invitations from colleagues, verify directly with them through another channel before clicking anything.

  3. Back up important work files to a separate location. If ransomware strikes, backups stored separately from your network are your lifeline. Ask your IT team about proper backup procedures.

  4. Talk to your IT department about this threat. Forward this article to your company's security team. They may not be aware of this specific technique yet.

  5. The Bigger Picture

    This attack represents a troubling evolution in cybercrime. Hackers are increasingly abusing trusted business tools like Teams, Slack, and Zoom to evade detection. As companies invest more in security, criminals adapt by hiding inside the very platforms we depend on for work. Staying informed about these emerging techniques is no longer optional for anyone who uses technology professionally or personally.

    How GetCyberRight Can Help

    Our Cyber Threat Radar tool tracks exactly these kinds of emerging attack techniques. It monitors how cybercriminals abuse trusted business communication platforms and translates complex threats into plain language you can actually use. When new dangers like the DragonForce Teams exploit appear, Cyber Threat Radar helps you understand what's at risk and what to do about it before your family or workplace becomes a victim.

    Protect Yourself

    Use our Cyber Threat Radar to check if you're affected and take action.

    Found this useful?

    Share it with someone who could use a heads-up.

    Share:

    Curated from trusted cybersecurity sources by GetCyberRight

    Source: GetCyberRight Intelligence

    Discussion

    0

    Sign in to join the discussion.

    Stay ahead of cyber threats

    Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.