Threats · 88 days ago
Trusted Microsoft Teams traffic can carry ransomware C2 and still look clean to network controls. The break is that a legitimate SaaS destination no longer means benign when the attacker rides the relay path itself, so allowlists and perimeter monitoring can miss the channel entirely.
Symantec says DragonForce used Backdoor.Turn in an attack on a major U.S. services firm. The malware obtained an anonymous Teams visitor token, used a real Microsoft TURN relay, and then talked to an attacker server through that path. It is the first known in-the-wild abuse of Microsoft Teams TURN relays for command-and-control.
That matters beyond Teams users. Any organization that trusts guest access and SaaS destinations for filtering now has a covert transport path to worry about, and the normal log trail can look like routine conferencing traffic even as the attacker keeps access alive before ransomware deployment.
6 sources covering this story
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
DragonForce-linked hackers used Backdoor.Turn to route C2 traffic through Microsoft Teams relay infrastructure during a U.S.
Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control.
Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic
Custom malware routed communications through legitimate Microsoft services, making malicious activity look like routine corporate collaboration
Cybercriminals mask malicious communications through Microsoft Teams relays - Help Net Security
DragonForce used Backdoor.Turn malware to hide command-and-control traffic through Microsoft Teams relay infrastructure.
DragonForce Ransomware Exploited Microsoft Teams to Hide Attack
Command and control traffic exploited a Teams visitor token to make malicious activity look legitimate to defenders
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure.
Part of the PlainSec briefing for 2026-06-17