logo

Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic

ID: bd30f9bd-6a54-596a-8141-a0b1451b4e6a

STIX ID: report--bd30f9bd-6a54-596a-8141-a0b1451b4e6a

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Guru Baran

...
...

Symantec uncovered a campaign in which the Backdoor.TURN Go-based RAT leveraged Microsoft Teams TURN relay servers to hide C2 communications during a DragonForce ransomware intrusion against a major U.S. services firm; attackers used DLL sideloading, abused vulnerable drivers (including HWAuidoOs2Ec.sys and other CVE-linked drivers), deployed a custom malicious driver to kill security processes, and conducted reconnaissance, credential theft, lateral movement, and long-term persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.