Skip to content
← All Threat Actors
Cybercrime high Malaysia (original hacktivist origins) / Eastern Europe (criminal expansion)

DragonForce (Hackledorb)

Cybercrime — ransomware operator and RaaS provider (Symantec: Hackledorb) · Financial — ransomware, extortion, and RaaS infrastructure provision

Reports 1
Active Since 2023
Last Reported 22 Jun 2026
Sectors Targeted finance, communications

Tactics, Techniques & Procedures (TTPs)

  • Backdoor.Turn: custom Go-based RAT tunnelling C2 through Microsoft Teams TURN relay using anonymous visitor tokens from Skype services
  • QUIC protocol covert sessions via Teams relay — all traffic appears as legitimate Teams meeting data, defeating DPI and network monitoring trusting Microsoft infrastructure
  • Microsoft SQL Server exploitation for initial access (unpatched internet-facing MSSQL instances)
  • BYOVD (Bring Your Own Vulnerable Driver): four documented techniques to terminate EDR processes before deploying Backdoor.Turn
  • Extended dwell time: 1-2 months of stealthy persistence before ransomware deployment documented
  • Active Directory enumeration, browser credential extraction, network scanning via 36 built-in Backdoor.Turn commands (including LDAP queries and TLS certificate capture)
  • RaaS infrastructure provision to other ransomware groups in addition to direct operations

Known Targets

Major US services firms (finance and professional services)UK retail sector organisationsEuropean manufacturing and logisticsEnterprise environments running Microsoft Teams and internet-facing MSSQL globally

Analyst Notes

DragonForce originated as a Malaysian hacktivist collective before evolving into a ransomware criminal operation (Hackledorb, active from June 2023). Backdoor.Turn's C2 channel — Microsoft's own Teams TURN relay infrastructure — is the first documented weaponisation of this technique. All traffic appears as legitimate Teams session data; organisations whose security tooling trusts Microsoft network traffic are blind to this C2 channel. DragonForce also provides RaaS infrastructure to other groups, meaning DragonForce-origin code may be deployed by affiliates rather than the core team directly, complicating attribution.

Also Known As

Hackledorb (Symantec designation)DragonForce Malaysia (hacktivist predecessor)