logo

Ransomware gang abuses Microsoft Teams relays to hide malicious traffic

ID: cbb8d81a-5eea-59a9-9fdd-115fa8cca95c

STIX ID: report--cbb8d81a-5eea-59a9-9fdd-115fa8cca95c

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Bill Toulas

...
...

Symantec reports that the DragonForce ransomware operation used a custom Go RAT called Backdoor.Turn to hide C2 communications inside Microsoft Teams TURN relays during a December 2025 attack on a major U.S. services company; the attackers gained initial access (likely via an MSSQL/SQL flaw), sideloaded a malicious DLL, leveraged BYOVD vulnerable drivers and a custom malicious driver for kernel privileges and security tool termination, performed reconnaissance and credential theft, exfiltrated data, and deployed ransomware—Symantec published IoCs and detailed the sophisticated TTPs and links to Scattered Spider.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.