Threat intelligence report · AlienVault OTX

Attackers Weaponize Microsoft Teams Relays to Stay Hidden

Attackers deploying DragonForce ransomware against a major U.S. services firm concealed their command-and-control traffic within Microsoft Teams relay infrastructure using Backdoor.Turn, a custom Go-based remote access trojan. This novel technique leverages anonymous Teams visitor tokens and TURN relay servers to mask malicious communications as legitimate Microsoft traffic. The intrusion lasted one to two months, beginning in December 2025 with exploitation of an SQL server vulnerability. Attackers employed sophisticated defense evasion tactics including DLL side-loading with VirtualBox executables and multiple Bring Your Own Vulnerable Driver techniques. They exploited a previously unknown vulnerability in Huawei's HWAuidoOs2Ec.sys driver, along with several other vulnerable drivers, to terminate security processes at kernel level. The campaign demonstrates DragonForce's evolution into a highly capable ransomware cartel with advanced operational maturity.

· unknown severity · unattributed attribution

Evidence and provenance

Original source
AlienVault OTX report ↗
Published
2026-07-16T14:19:54.502000Z
Confidence basis
No actor match
Record ID
a98b200b2cb9016030c8

Vulnerabilities

CVE-2023-52271, CVE-2025-1055, CVE-2025-61155

Affected sectors

telecommunications

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.