logo

Microsoft Teams Relay Abused to Stealthily Route Malware Communications

ID: 5be41e95-5c0a-537c-9aab-72effc269aa2

STIX ID: report--5be41e95-5c0a-537c-9aab-72effc269aa2

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Lucas Martin

...
...

Symantec investigated and attributed a targeted ransomware campaign by the DragonForce group that covertly tunneled command-and-control through Microsoft Teams TURN relays using a custom Go-based RAT (Backdoor.Turn). The intrusion leveraged an initial SQL/MSSQL compromise or purchased access, sideloaded a malicious DLL, deployed kernel-level BYOVD techniques including a purpose-built malicious driver (Abyss Worker) and exploited multiple signed-driver vulnerabilities to disable endpoint security, and maintained persistence for 1–2 months while exfiltrating credentials and mapping AD environments. The report includes detailed TTPs and multiple IoCs (SHA-256 hashes, an IP, and a URL).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.