logo

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

ID: 55d32ded-3c8e-508a-ad9a-868b92d01aca

STIX ID: report--55d32ded-3c8e-508a-ad9a-868b92d01aca

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: [email protected] (The Hacker News)

...
...

Symantec/Carbon Black researchers link the DragonForce ransomware group to a novel Go-based remote access trojan named Backdoor.Turn that conceals C2 traffic by obtaining anonymous Microsoft Teams visitor tokens and relaying through legitimate TURN infrastructure before establishing QUIC sessions to attacker C2. The intrusion—observed against a major U.S. services firm—used DLL sideloading, BYOVD (vulnerable driver) techniques to disable security software, injected the RAT into a legitimate process post-ransomware deployment to maintain access, and supports wide-ranging capabilities (command execution, AD/LDAP reconnaissance, credential theft, lateral movement).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.