Attackers Weaponize Microsoft Teams Relays to Stay Hidden
Attackers deploying DragonForce ransomware against a major U.S. services firm concealed their command-and-control traffic within Microsoft Teams relay infrastructure using Backdoor.Turn, a custom Go-based remote access trojan. This novel technique leverages anonymous Teams visitor tokens and TURN relay servers to mask malicious communications as legitimate Microsoft traffic. The intrusion lasted one to two months, beginning in December 2025 with exploitation of an SQL server vulnerability. Attackers employed sophisticated defense evasion tactics including DLL side-loading with VirtualBox executables and multiple Bring Your Own Vulnerable Driver techniques. They exploited a previously unknown vulnerability in Huawei's HWAuidoOs2Ec.sys driver, along with several other vulnerable drivers, to terminate security processes at kernel level. The campaign demonstrates DragonForce's evolution into a highly capable ransomware cartel with advanced operational maturity.
· unknown severity · unattributed attribution
Evidence and provenance
- Original source
- AlienVault OTX report ↗
- Published
- 2026-07-16T14:19:54.502000Z
- Confidence basis
- No actor match
- Record ID
a98b200b2cb9016030c8
Vulnerabilities
CVE-2023-52271, CVE-2025-1055, CVE-2025-61155
Affected sectors
telecommunications
Use and citation
Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.