Trusted Microsoft Teams traffic can carry ransomware C2 and still look clean to network controls. The break is that a legitimate SaaS destination no longer means benign when the attacker rides the relay path itself, so allowlists and perimeter monitoring can miss the channel entirely.
Symantec says DragonForce used Backdoor.Turn in an attack on a major U.S. services firm. The malware obtained an anonymous Teams visitor token, used a real Microsoft TURN relay, and then talked to an attacker server through that path. It is the first known in-the-wild abuse of Microsoft Teams TURN relays for command-and-control.
That matters beyond Teams users. Any organization that trusts guest access and SaaS destinations for filtering now has a covert transport path to worry about, and the normal log trail can look like routine conferencing traffic even as the attacker keeps access alive before ransomware deployment.