# DragonForce Hackers Weaponize Microsoft Teams Relays to Hide Backdoor C2 Traffic
Threat actors behind the notorious DragonForce ransomware gang have evolved their operational security tradecraft by deploying a custom Go-based remote access trojan (RAT) called Backdoor.Turn that tunnels command-and-control (C2) traffic through Microsoft Teams relay infrastructure—a technique that exploits the trust placed in a mainstream business communication platform to evade network detection and incident response teams.
Security researchers at Broadcom's Symantec and Carbon Black divisions discovered the backdoor during incident response work following deployment against a major U.S. services firm. The sophisticated approach signals a maturation in adversary techniques, where traditional malware communication channels are abandoned in favor of blending malicious traffic with the noise of legitimate enterprise software.
## The Threat: Backdoor.Turn Explained
Backdoor.Turn is a modular remote access trojan written in Go—a programming language increasingly favored by threat actors for its compilation characteristics and cross-platform compatibility. The malware operates as a second-stage payload typically delivered after initial network compromise, providing attackers persistent, interactive access to compromised systems.
Key capabilities of Backdoor.Turn include:
The backdoor's primary innovation lies not in its malware capabilities, which are relatively standard for RATs, but rather in how it communicates with its operators. Rather than connecting to traditional C2 servers that can be monitored, blocked, or attributed through passive DNS and network telemetry, Backdoor.Turn encapsulates C2 traffic within Microsoft Teams relay connections—essentially hiding unauthorized command traffic inside legitimate business communications.
## Background and Context: Who Is DragonForce?
DragonForce has emerged as a significant threat actor in the ransomware-as-a-service (RaaS) ecosystem, known for targeting mid-to-large organizations across critical infrastructure, healthcare, manufacturing, and professional services sectors. The group is recognized for:
The use of Backdoor.Turn represents a tactical shift in DragonForce's approach. Previously, the group relied on more commodity malware and publicly available exploitation tools. The development or acquisition of a custom Go-based RAT suggests either increased resources, partnerships with other threat actors, or acquisition of tools from underground markets—all indicators of escalating threat maturity.
## Technical Details: How Teams Relays Become C2 Conduits
Microsoft Teams, like most enterprise communication platforms, uses relay infrastructure to facilitate communication between clients and backend services. These relays are designed to support legitimate business functions: bridging connections across firewalls, enabling video and voice calls, and routing messages reliably.
The attack chain exploits this architecture:
1. Initial Compromise: Attacker gains initial foothold through phishing, credential compromise, or vulnerability exploitation
2. Backdoor.Turn Deployment: Second-stage payload is delivered to establish persistent access
3. Teams Channel Hijacking or Abuse: The backdoor creates or exploits Teams connections to relay C2 traffic through legitimate Microsoft infrastructure
4. Command Obfuscation: Attacker commands are embedded within Teams protocol traffic, appearing indistinguishable from normal user activity
5. Data Exfiltration: Stolen credentials, file contents, and reconnaissance data flow through the same Teams relay channel
Why This Approach Is Effective:
| Factor | Impact |
|--------|--------|
| Legitimate Source | Teams traffic is inherently trusted; blocking it disrupts business operations |
| Encryption in Transit | Traffic is encrypted by Microsoft, obscuring payloads from network inspection |
| Attribution Opacity | C2 communication traces back to Microsoft infrastructure, not attacker-controlled servers |
| Detection Evasion | Endpoint detection tools struggle to flag Teams process activity as anomalous |
| Rate Limiting Bypass | Legitimate Teams infrastructure absorbs inquiry traffic without triggering alerts |
Symantec and Carbon Black researchers noted that traditional C2 detection signatures and network-based indicators of compromise (IoCs) were largely ineffective against this approach, as the malware blended seamlessly with expected Teams client behavior.
## Implications for Organizations
This discovery carries urgent implications across multiple organizational domains:
### Security Operations
Organizations relying solely on network-level C2 detection will find this attack largely invisible. A host communicating with Microsoft Teams infrastructure is expected behavior; detecting unauthorized C2 requires behavioral analysis at the process level and authentication-aware network monitoring that can distinguish between legitimate Teams clients and Backdoor.Turn instances.
### Incident Response
Detection delays are likely to extend significantly. If an adversary maintains C2 through Teams relays for weeks before ransomware deployment, forensic analysis becomes exponentially more complex. Organizations must implement:
### Identity and Access Management
The reliance on Teams relay infrastructure suggests adversaries may first compromise legitimate Teams accounts, enabling them to authenticate to Teams infrastructure legitimately—transforming an account takeover into a persistence mechanism that looks entirely benign in authentication logs.
## Recommendations for Defense
Organizations should implement a defense-in-depth strategy specifically addressing this threat pattern:
Immediate Actions:
Medium-Term Improvements:
Strategic Priorities:
---
## HackWire Analysis
The weaponization of Microsoft Teams relays by DragonForce represents a critical inflection point in adversary evasion tactics: the death of distinctive C2 signatures.
For a decade, security teams could rely on identifying malware command-and-control communication through network fingerprinting—distinctive protocol patterns, specific port usage, or attacker-controlled IP addresses. That approach is now obsolete. Backdoor.Turn forces a fundamental shift in how organizations conceptualize threat detection: if an attacker can hide malicious activity inside a mainstream productivity platform your organization already uses and trusts, then *network traffic alone cannot be your primary detection mechanism.*
This signals three broader trends worth monitoring. First, we're seeing a bifurcation in threat actor sophistication. Commodity ransomware operators still use obvious C2 infrastructure; sophisticated groups like DragonForce now engineer custom malware specifically to abuse legitimate platforms. This creates a widening detection gap where only well-resourced organizations with mature behavioral EDR can respond effectively. Second, Microsoft's infrastructure—Teams relays, OneDrive, SharePoint—is becoming a primary attack surface. Microsoft's scale and trust make it an irresistible target for evasion. Expect similar discoveries in Exchange, Outlook, and other Microsoft services as researchers examine them more closely. Third, organizations face an impossible choice: block legitimate Microsoft services to prevent C2 abuse, or accept that Teams (and similar platforms) are now potential malware highways. Most will choose acceptance and hope behavioral detection catches the adversary. They'll be wrong, often.
The real risk isn't that DragonForce has found a clever backdoor technique—it's that this technique is now discoverable, reproducible, and accessible to dozens of other ransomware gangs. Expect variants within weeks. Organizations without behavioral process monitoring and authentication-aware network insights will be blind to this threat class entirely.
— HackWire Editorial
---
## Related Coverage