Threats & Adversaries · Ransomware
Teams Traffic Became Ransomware Cover Trusted Microsoft Teams traffic can carry ransomware C2 and still look clean to network controls. The break is that a legitimate SaaS destination no longer means benign when the attacker rides the relay path itself, so allowlists and perimeter monitoring can miss the channel entirely.
Symantec says DragonForce used Backdoor.Turn in an attack on a major U.S. services firm. The malware obtained an anonymous Teams visitor token, used a real Microsoft TURN relay, and then talked to an attacker server through that path. It is the first known in-the-wild abuse of Microsoft Teams TURN relays for command-and-control.
That matters beyond Teams users. Any organization that trusts guest access and SaaS destinations for filtering now has a covert transport path to worry about, and the normal log trail can look like routine conferencing traffic even as the attacker keeps access alive before ransomware deployment.
6 sources · Jun 18
Timeline Sources Jun 18 The Hacker News
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
DragonForce-linked hackers used Backdoor.Turn to route C2 traffic through Microsoft Teams relay infrastructure during a U.S.
original Jun 17 SecurityWeek
Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control.
original Jun 16 The Register Security
Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic
Custom malware routed communications through legitimate Microsoft services, making malicious activity look like routine corporate collaboration
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-06-16
Every edition of this story: Teams Traffic Became Ransomware Cover
More from today
Threats & Adversaries · Ransomware
Teams Traffic Became Ransomware Cover Trusted Microsoft Teams traffic can carry ransomware C2 and still look clean to network controls. The break is that a legitimate SaaS destination no longer means benign when the attacker rides the relay path itself, so allowlists and perimeter monitoring can miss the channel entirely.
Symantec says DragonForce used Backdoor.Turn in an attack on a major U.S. services firm. The malware obtained an anonymous Teams visitor token, used a real Microsoft TURN relay, and then talked to an attacker server through that path. It is the first known in-the-wild abuse of Microsoft Teams TURN relays for command-and-control.
That matters beyond Teams users. Any organization that trusts guest access and SaaS destinations for filtering now has a covert transport path to worry about, and the normal log trail can look like routine conferencing traffic even as the attacker keeps access alive before ransomware deployment.
6 sources · Jun 18
Timeline Sources Jun 18 The Hacker News
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
DragonForce-linked hackers used Backdoor.Turn to route C2 traffic through Microsoft Teams relay infrastructure during a U.S.
original Jun 17 SecurityWeek
Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control.
original Jun 16 The Register Security
Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic
Custom malware routed communications through legitimate Microsoft services, making malicious activity look like routine corporate collaboration
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-06-16
Every edition of this story: Teams Traffic Became Ransomware Cover
More from today