Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

In December 2025, the DragonForce ransomware group executed a sophisticated multi-stage attack against a major U.S. services company, using a novel backdoor that disguises malicious command-and-control traffic as legitimate Microsoft Teams network activity, effectively defeating standard network monitoring and geo-blocking controls. The attack chain combined kernel-level driver exploitation across at least four vulnerable third-party drivers to disable endpoint defenses, followed by data exfiltration and ransomware deployment in a double-extortion pattern. Organizations running Microsoft Teams, MSSQL, or any of the identified vulnerable drivers face elevated risk of undetected compromise; the attack’s use of trusted Microsoft infrastructure as a C2 channel represents a significant detection gap for most enterprise security stacks.

Author

Tech Jacks Solutions