Close Menu
    What's Hot

    McCarthy Aide’s Tell-All Book Recounts Trump’s Expletive-Filled Threats to G.O.P.

    US progressive Lewis George on track to become DC mayor after Trump threats | Politics News

    The Iran War Damaged U.S.-India Ties – Foreign Policy

    Facebook X (Twitter) Instagram
    Trending
    • McCarthy Aide’s Tell-All Book Recounts Trump’s Expletive-Filled Threats to G.O.P.
    • US progressive Lewis George on track to become DC mayor after Trump threats | Politics News
    • The Iran War Damaged U.S.-India Ties – Foreign Policy
    • BHP takes $2.3bn writedown on Canadian fertiliser project
    • Brookfield Business Corporation (BBUC:CA) Shareholder/Analyst Call Prepared Remarks Transcript
    • General Intuition in talks to raise $300M at around $2B valuation
    • Supreme Court Narrows Law Banning Drug Users From Owning Guns
    • Gulf States Are Frustrated by Failure to Tackle Iran’s Missiles, Analysts Say
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

    adminBy adminJune 18, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 18, 2026Remote Access Trojan / Ransomware

    DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

    Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure.

    According to findings from Broadcom-owned Symantec and Carbon Black, the backdoor was deployed against a major U.S. services firm. The name of the company was not disclosed.

    “Backdoor.Turn obtains an anonymous Teams visitor token from Microsoft’s Skype-backed identity services, uses a legitimate Microsoft TURN relay to set up the connection, and then runs a QUIC session to the attacker’s real command-and-control (C2) server,” the Threat Hunter Team said in a report shared with The Hacker News.

    “To network defenders, the only traffic they could see was outbound connections to legitimate Microsoft Teams servers. The attackers were on the victim network for between one and two months.”

    The development marks the first publicly documented instance of the threat actors abusing Microsoft’s Traversal Using Relays around NAT (TURN) relay infrastructure.

    Cybersecurity

    It’s suspected the threat actor obtained initial access by exploiting a vulnerability in either an SQL or MS-SQL server, although the exact nature of the flaw is unknown. It’s also possible that the access was acquired from an initial access broker (IAB).

    Initial malicious activity on the victim network began in December 2025, with the attackers running a PowerShell command to drop a ZIP archive under the pretext of a tech support hotfix. The ZIP file responsible for launching a DLL side-loading attack, which then runs a rogue DLL to conduct reconnaissance, set up persistence, and silence security software using a Huawei driver (“HWAuidoOs2Ec.sys”).

    This is achieved by means of an attack technique called bring your own vulnerable driver (BYOVD) technique. The driver has been put to use in a large-scale malvertising campaign targeting U.S.-based individuals searching for tax-related documents, although this is said to have taken place after the ransomware incident.

    Some of the other drivers used for this purpose are listed below –

    What’s notable about the attack is the execution of Backdoor.Turn by injecting it into the legitimate “DbgView64.exe” process after the DragonForce ransomware has been deployed. This suggests an attempt to maintain continued access to the compromised host for later attacks or reselling it for profit.

    Backdoor.Turn’s underlying TURN-based mechanism leans on a stealthy C2 communication technique called Ghost Calls that was documented by Praetorian in August 2024. The backdoor supports a wide range of capabilities, including command execution, process creation, network scanning, LDAP and Active Directory search, credential-based lateral movement, and browser credential theft.

    Cybersecurity

    “The backdoor requests a visitor token from the Microsoft Teams/Skype backend, uses that token to interact with Teams-associated infrastructure (TURN relay), and then establishes outbound connectivity,” Symantec and Carbon Black explained.

    “It obtains a Teams visitor (anonymous) authentication token backed by Skype identity services. It then uses a legitimate Microsoft server as the TURN relay server during connection setup. After relay-assisted setup, the malware establishes a direct QUIC session to the C&C server, which is malicious.”

    The findings paint a picture of a hacking group leaning on sophisticated cyber tradecraft to pull off high-impacted targeted attacks, while leaving victims in the dark about covert data exfiltration. This is particularly significant as Hackledorb, the threat actor behind DragonForce, has pivoted from a conventional ransomware-as-a-service (RaaS) model to a highly organized, formalized cartel structure.

    “The operational timeline reveals a pattern of continuous capability development, with the adoption of highly advanced techniques becoming a hallmark of their post-2025 activity,” the company said. “The deployment of Backdoor.Turn, combined with their multi-vector BYOVD evasion, marks them as one of the most capable and persistent ransomware groups operating today.”

    abuse Backdoor.Turn DragonForce hackers Hide Microsoft relays teams Traffic
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleSleep Number Corporation stock will be delisted from Nasdaq after Chapter 11 bankruptcy; shares plummet
    Next Article Tech Workers Maxed Out Their A.I. Use. Now They’re Trying to Minimize It.
    admin
    • Website

    Related Posts

    World Cup overreactions: Takeaways now that all 48 teams played first games

    June 18, 2026

    The Scripts on Your Checkout Page Are Now a PCI DSS Problem

    June 18, 2026

    Knicks owner James Dolan’s second apron comments raise big questions on team’s future roster

    June 18, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    McCarthy Aide’s Tell-All Book Recounts Trump’s Expletive-Filled Threats to G.O.P.

    US progressive Lewis George on track to become DC mayor after Trump threats | Politics News

    The Iran War Damaged U.S.-India Ties – Foreign Policy

    BHP takes $2.3bn writedown on Canadian fertiliser project

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by