logo

DragonForce Hides Backdoor C2 Inside Microsoft Teams TURN Relays

ID: 6949a3dd-994e-57cc-ba44-0efaa67f46a0

STIX ID: report--6949a3dd-994e-57cc-ba44-0efaa67f46a0

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Do Son

...
...

Symantec uncovered Backdoor.Turn, a Go-based Microsoft Teams backdoor used by DragonForce/Hackledorb to hide QUIC-based C2 inside Microsoft Teams TURN relays, enabling stealthy command channels, credential theft, Active Directory reconnaissance, lateral movement and the deployment of DragonForce ransomware against a major U.S. services firm; initial access likely came via an SQL/MSSQL exploit or purchased access, followed by DLL side‑loading of a signed VirtualBox/DbgView binary, abuse of vulnerable drivers (including several tracked CVEs), and extended dwell time — Symantec provides detection and mitigation guidance such as hunting for non-Teams binaries establishing Teams visitor/TURN sessions, blocking known vulnerable drivers, and auditing account/firewall changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.