Minacce · 103 giorni fa
Il problema non è solo che DragonForce ha usato Teams come esca: ha trasformato il relay legittimo di Microsoft in un canale C2, così i controlli di rete vedono traffico SaaS fidato mentre il malware parla con l’attaccante. Questo rompe l’assunzione pratica che una destinazione Microsoft 365 o Teams sia, di per sé, un segnale benigno.
Symantec descrive Backdoor.Turn come il primo malware noto visto in natura a abusare dei TURN relay di Microsoft Teams per il command-and-control. Il gruppo ha ottenuto un anonymous Teams visitor token, si è agganciato a un relay legittimo e ha poi mantenuto accesso prolungato contro una grande società di servizi statunitense, prima di arrivare al ransomware; il caso conferma che l’apparenza di traffico Teams può coprire attività ostile.
Per chi consente guest access o affida il filtraggio a allowlist SaaS, il rischio non è solo la singola intrusione ma il buco nel modello di fiducia: il canale di conferenza può diventare trasporto covert per C2, lateral movement e preparazione pre-ransomware senza lasciare un pattern di rete ovvio.
6 fonti che coprono questa storia
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
DragonForce-linked hackers used Backdoor.Turn to route C2 traffic through Microsoft Teams relay infrastructure during a U.S.
Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control.
Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic
Custom malware routed communications through legitimate Microsoft services, making malicious activity look like routine corporate collaboration
Cybercriminals mask malicious communications through Microsoft Teams relays - Help Net Security
DragonForce used Backdoor.Turn malware to hide command-and-control traffic through Microsoft Teams relay infrastructure.
DragonForce Ransomware Exploited Microsoft Teams to Hide Attack
Command and control traffic exploited a Teams visitor token to make malicious activity look legitimate to defenders
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-17