DragonForce (Hackledorb)
Cybercrime — ransomware operator and RaaS provider (Symantec: Hackledorb) · Financial — ransomware, extortion, and RaaS infrastructure provision
Tactics, Techniques & Procedures (TTPs)
- Backdoor.Turn: custom Go-based RAT tunnelling C2 through Microsoft Teams TURN relay using anonymous visitor tokens from Skype services
- QUIC protocol covert sessions via Teams relay — all traffic appears as legitimate Teams meeting data, defeating DPI and network monitoring trusting Microsoft infrastructure
- Microsoft SQL Server exploitation for initial access (unpatched internet-facing MSSQL instances)
- BYOVD (Bring Your Own Vulnerable Driver): four documented techniques to terminate EDR processes before deploying Backdoor.Turn
- Extended dwell time: 1-2 months of stealthy persistence before ransomware deployment documented
- Active Directory enumeration, browser credential extraction, network scanning via 36 built-in Backdoor.Turn commands (including LDAP queries and TLS certificate capture)
- RaaS infrastructure provision to other ransomware groups in addition to direct operations
Known Targets
Analyst Notes
DragonForce originated as a Malaysian hacktivist collective before evolving into a ransomware criminal operation (Hackledorb, active from June 2023). Backdoor.Turn's C2 channel — Microsoft's own Teams TURN relay infrastructure — is the first documented weaponisation of this technique. All traffic appears as legitimate Teams session data; organisations whose security tooling trusts Microsoft network traffic are blind to this C2 channel. DragonForce also provides RaaS infrastructure to other groups, meaning DragonForce-origin code may be deployed by affiliates rather than the core team directly, complicating attribution.
Also Known As