DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months
2026-06-18T02:51:42Z•d08db20cc31a9e5b199132f21328a0501f0fd11272b20d36a24a11a0db6451a3
CISA KEVCVE-2026-20262CVE-2026-48907active exploitationandroid banking trojanbackdoorcisco catalyst sd-wancommand-and-controldata breachdragonforceedtech breachesextortionfishmongerfortisandboxfulcrumsecirhythmkernel driver stealthmicrosoft teams abusenovo nordiskransomwarerokarollasprysocksuefi bootkit
What happened
Multiple high-impact incidents and active exploitations were reported: DragonForce operators hid C2 traffic by relaying through Microsoft Teams to remain undetected for weeks while deploying ransomware; CISA added the Widget Factory Joomla Content Editor flaw (CVE-2026-48907, CVSS 10.0) to its Known Exploited Vulnerabilities catalog; a new Rokarolla Android banking trojan targets 217 banking/crypto apps and disables Play Protect; China-linked FishMonger ported SprySOCKS to Windows with kernel-level stealth and potential UEFI bootkit indicators; several organizations suffered data-theft extortn
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d08db20cc31a9e5b199132f21328a0501f0fd11272b20d36a24a11a0db6451a3
- Enrichment time
- 2026-06-18T02:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.