Microsoft Teams Relay Abused by Hackers to Hide Malicious Traffic
ID: 072f5ef4-78dd-5444-bea7-ce5bed2a272b
STIX ID: report--072f5ef4-78dd-5444-bea7-ce5bed2a272b
Feed Name: GBHackers
### Executive summary Security researchers observed a targeted ransomware campaign attributed to the DragonForce group that used a novel Go-based RAT (Backdoor.Turn) to tunnel C2 through Microsoft Teams TURN relays and QUIC sessions, rendering communications indistinguishable from legitimate Teams traffic. Attackers gained initial access (likely via an SQL/MSSQL vulnerability or purchased access), used DLL sideloading and BYOVD (abusing signed vulnerable drivers and a custom driver named Abyss Worker) for kernel-level evasion and persistence, performed reconnaissance and credential harvesting, exfiltrated data, and executed DragonForce ransomware; the operation demonstrates advanced stealth by leveraging trusted enterprise infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
