logo

Microsoft Teams Relay Abused by Hackers to Hide Malicious Traffic

ID: 072f5ef4-78dd-5444-bea7-ce5bed2a272b

STIX ID: report--072f5ef4-78dd-5444-bea7-ce5bed2a272b

Feed Name: GBHackers

Threat Score
82/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Divya

...
...

### Executive summary Security researchers observed a targeted ransomware campaign attributed to the DragonForce group that used a novel Go-based RAT (Backdoor.Turn) to tunnel C2 through Microsoft Teams TURN relays and QUIC sessions, rendering communications indistinguishable from legitimate Teams traffic. Attackers gained initial access (likely via an SQL/MSSQL vulnerability or purchased access), used DLL sideloading and BYOVD (abusing signed vulnerable drivers and a custom driver named Abyss Worker) for kernel-level evasion and persistence, performed reconnaissance and credential harvesting, exfiltrated data, and executed DragonForce ransomware; the operation demonstrates advanced stealth by leveraging trusted enterprise infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.