DragonForce ransomware used Microsoft Teams relay infrastructure to hide malware traffic in a real attack

DragonForce ransomware operators used Microsoft Teams network relays to disguise malware communications during an attack on a major U.S. services company. Symantec says the attackers deployed a custom Go-based backdoor called Backdoor.Turn that abused Teams' TURN relays (servers that help route traffic when direct connections fail) to mask command-and-control traffic as Microsoft activity. The December 2025 intrusion also used bring-your-own-vulnerable-driver tactics, including HWAuidoOs2Ec.sys, wsftprm.sys (CVE-2023-52271), GameDriverx64.sys (CVE-2025-61155), and K7RKScan.sys (CVE-2025-1055), before data theft and ransomware deployment.
Why it matters: This matters because defenders may see the malware's traffic as legitimate Microsoft Teams activity, making detection and blocking harder during a ransomware attack. Organizations should review Microsoft Teams-related network trust assumptions, hunt for the listed indicators, and prioritize controls against driver-based security-tool tampering and suspicious use of SQL/MSSQL servers.

Sources

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
info@thehackernews.com (The Hacker News) 2026.06.18 99% relevant
This article appears to cover the same underlying event and adds reporting on DragonForce abusing Microsoft Teams relays to mask backdoor command-and-control traffic during an actual ransomware intrusion.
Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
Ionut Arghire 2026.06.17 99% relevant
This article is a direct report on the same incident, adding specifics that the malware is a new Go-based backdoor dubbed Backdoor.Turn, that it obtains anonymous Teams visitor tokens and uses Microsoft TURN relays plus QUIC to mask command-and-control traffic, and that the intrusion likely began via an unknown SQL or MSSQL server vulnerability before ransomware deployment and post-encryption persistence.
Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic
2026.06.16 98% relevant
This is the same underlying event: Symantec's report that DragonForce compromised a major U.S. services company and used Microsoft Teams and Skype backend infrastructure plus a Microsoft TURN relay to conceal Backdoor.Turn command-and-control traffic. The article adds detail on the anonymous visitor token request, QUIC connection flow, two-month dwell time, and the possibility that the backdoor was left behind after ransomware deployment for persistence or resale of access.
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
Bill Toulas 2026.06.16 100% relevant
This article establishes a distinct story because it reports the first known in-the-wild malware abuse of Microsoft Teams TURN relay infrastructure by DragonForce during a real ransomware intrusion, rather than a patch, advisory, or previously tracked breach.
← Back to all stories