DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months

2026-06-18T02:51:42Zd08db20cc31a9e5b199132f21328a0501f0fd11272b20d36a24a11a0db6451a3
CISA KEVCVE-2026-20262CVE-2026-48907active exploitationandroid banking trojanbackdoorcisco catalyst sd-wancommand-and-controldata breachdragonforceedtech breachesextortionfishmongerfortisandboxfulcrumsecirhythmkernel driver stealthmicrosoft teams abusenovo nordiskransomwarerokarollasprysocksuefi bootkit

What happened

Multiple high-impact incidents and active exploitations were reported: DragonForce operators hid C2 traffic by relaying through Microsoft Teams to remain undetected for weeks while deploying ransomware; CISA added the Widget Factory Joomla Content Editor flaw (CVE-2026-48907, CVSS 10.0) to its Known Exploited Vulnerabilities catalog; a new Rokarolla Android banking trojan targets 217 banking/crypto apps and disables Play Protect; China-linked FishMonger ported SprySOCKS to Windows with kernel-level stealth and potential UEFI bootkit indicators; several organizations suffered data-theft extortn

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d08db20cc31a9e5b199132f21328a0501f0fd11272b20d36a24a11a0db6451a3
Enrichment time
2026-06-18T02:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.