DragonForce ransomware operators used Microsoft Teams network relays to disguise malware communications during an attack on a major U.S. services company. Symantec says the attackers deployed a custom Go-based backdoor called Backdoor.Turn that abused Teams' TURN relays (servers that help route traffic when direct connections fail) to mask command-and-control traffic as Microsoft activity. The December 2025 intrusion also used bring-your-own-vulnerable-driver tactics, including HWAuidoOs2Ec.sys, wsftprm.sys (CVE-2023-52271), GameDriverx64.sys (CVE-2025-61155), and K7RKScan.sys (CVE-2025-1055), before data theft and ransomware deployment.
Why it matters: This matters because defenders may see the malware's traffic as legitimate Microsoft Teams activity, making detection and blocking harder during a ransomware attack. Organizations should review Microsoft Teams-related network trust assumptions, hunt for the listed indicators, and prioritize controls against driver-based security-tool tampering and suspicious use of SQL/MSSQL servers.
info@thehackernews.com (The Hacker News)
2026.06.18
99% relevant
This article appears to cover the same underlying event and adds reporting on DragonForce abusing Microsoft Teams relays to mask backdoor command-and-control traffic during an actual ransomware intrusion.
Ionut Arghire
2026.06.17
99% relevant
This article is a direct report on the same incident, adding specifics that the malware is a new Go-based backdoor dubbed Backdoor.Turn, that it obtains anonymous Teams visitor tokens and uses Microsoft TURN relays plus QUIC to mask command-and-control traffic, and that the intrusion likely began via an unknown SQL or MSSQL server vulnerability before ransomware deployment and post-encryption persistence.
2026.06.16
98% relevant
This is the same underlying event: Symantec's report that DragonForce compromised a major U.S. services company and used Microsoft Teams and Skype backend infrastructure plus a Microsoft TURN relay to conceal Backdoor.Turn command-and-control traffic. The article adds detail on the anonymous visitor token request, QUIC connection flow, two-month dwell time, and the possibility that the backdoor was left behind after ransomware deployment for persistence or resale of access.
Bill Toulas
2026.06.16
100% relevant
This article establishes a distinct story because it reports the first known in-the-wild malware abuse of Microsoft Teams TURN relay infrastructure by DragonForce during a real ransomware intrusion, rather than a patch, advisory, or previously tracked breach.
← Back to all stories