DragonForce Hides Backdoor C2 Inside Microsoft Teams TURN Relays
ID: 6949a3dd-994e-57cc-ba44-0efaa67f46a0
STIX ID: report--6949a3dd-994e-57cc-ba44-0efaa67f46a0
Feed Name: securityonline.info
Symantec uncovered Backdoor.Turn, a Go-based Microsoft Teams backdoor used by DragonForce/Hackledorb to hide QUIC-based C2 inside Microsoft Teams TURN relays, enabling stealthy command channels, credential theft, Active Directory reconnaissance, lateral movement and the deployment of DragonForce ransomware against a major U.S. services firm; initial access likely came via an SQL/MSSQL exploit or purchased access, followed by DLL side‑loading of a signed VirtualBox/DbgView binary, abuse of vulnerable drivers (including several tracked CVEs), and extended dwell time — Symantec provides detection and mitigation guidance such as hunting for non-Teams binaries establishing Teams visitor/TURN sessions, blocking known vulnerable drivers, and auditing account/firewall changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
