Full Report
“There are paths that lead into darkness, and once you set foot upon them, the way back is never certain. Somewhere ahead, the dragon waits.” One of the latest operations uncovered involving DragonForce is the abuse of legitimate TURN (Traversal Using Relays around NAT) servers to encapsulate communications between a malicious implant and the attacker’s […]
Analysis Summary
# Threat Actor: DragonForce
## Attribution & Identity
* **Actor Identification:** DragonForce is identified as an evolving cybercriminal entity that has transitioned from a traditional Ransomware-as-a-Service (RaaS) model to a more sophisticated "ransomware cartel."
* **Aliases:** None explicitly listed in the text, though the group is distinguished by its specific use of TURN/MQTT communication protocols.
* **Associations:** Linked to previous campaigns involving malicious MS Teams backdoors as reported by Symantec.
## Activity Summary
The article details a sophisticated multi-stage campaign focusing on the deployment of two distinct backdoors. One is a memory-only Go-based implant used during initial deployment, and the other is a persistent backdoor designed for long-term residency. A defining characteristic of this activity is the abuse of legitimate **TURN (Traversal Using Relays around NAT)** servers—specifically those belonging to Microsoft Teams—to mask Command and Control (C2) traffic and bypass network defenses.
## Tactics, Techniques & Procedures
* **Abuse of Legitimate Services:** Utilizing Microsoft Teams TURN servers to encapsulate malicious traffic, making it appear as legitimate communication.
* **Redundant C2 Channels:** Implementation of **MQTT (Message Queuing Telemetry Transport)** as a secondary communication protocol if TURN communication fails.
* **DLL Sideloading:** Abuse of the legitimate `javaw.exe` to load a malicious loader (`jli.dll`).
* **Defense Evasion:**
* Use of **DPAPI** (Data Protection API) to encrypt payloads (`rvsdiqw.txt`), making them hardware-dependent and difficult to analyze in sandboxes.
* Polymorphic loaders (the hash of `jli.dll` changes per system).
* Memory-only injection of the **Shell.dll** binary.
* **Persistence:** Establishing residency via Scheduled Tasks.
* **MITRE ATT&CK IDs:**
* T1574.002 (DLL Side-Loading)
* T1053.005 (Scheduled Task)
* T1027 (Obfuscated Files or Information)
* T1132.001 (Data Encoding: Standard Encoding)
* T1105 (Ingress Tool Transfer)
## Targeting
* **Sectors:** Not explicitly defined in the article, though the group traditionally targets a wide range of industries consistent with "ransomware cartel" activity.
* **Geography:** Global (implied by the use of international C2 infrastructure and compromised WordPress sites in Italy, Poland, and Argentina).
* **Victims:** Specific victims are not named, but the infrastructure involves compromised WordPress sites (e.g., `accesscapfunding[.]com`, `prolabgest[.]it`).
## Tools & Infrastructure
* **Malware Families:**
* **Shell.dll:** A Go-based implant injected into memory.
* **jli.dll:** A first-stage loader.
* **Infrastructure:**
* **C2 IPs:**
* 188.190.4[.]111
* 62.164.177[.]145 (Port 3478)
* 217.156.8[.]181 (Port 7586)
* **Compromised Web Infrastructure (URL Defanged):**
* accesscapfunding[.]com
* paigeinfull[.]com
* cncluxurywater[.]com
* printpro.com[.]pl
* pymsolutions[.]com.ar
* whapido.com[.]ar
* prolabgest[.]it
## Implications
DragonForce has evolved into a highly mature operational threat. Their use of non-standard protocols like TURN and MQTT for C2 traffic suggests a high level of technical proficiency aimed at circumventing standard EDR and network traffic analysis tools. The professionalization into a "cartel" indicates they are likely building persistent access for repeated exploitation or to sell access to other high-tier threat actors.
## Mitigations
* **Network Filtering:** Monitor and restrict outbound traffic to unknown or unauthorized TURN/STUN and MQTT servers. Specifically, scrutinize high volumes of traffic to TURN servers if not typically used by your organization.
* **Process Monitoring:** Monitor `javaw.exe` for unusual child processes or the loading of unsigned/unexpected DLLs in its directory.
* **Persistence Detection:** Regularly audit Scheduled Tasks for suspicious entries, particularly those calling binaries in non-standard or temporary directories.
* **IoC Blocking:** Implement blocking for the identified C2 IPs and compromised domains at the firewall and web proxy levels.