# Microsoft Teams Servers Weaponized as Backdoor Command Center in Advanced Ransomware Campaign
Symantec researchers discover DragonForce group deploying sophisticated Go-based malware that abuses legitimate Microsoft infrastructure to evade detection
A sophisticated ransomware campaign attributed to the DragonForce group has introduced a novel evasion technique that weaponizes Microsoft Teams infrastructure for command-and-control (C&C) communications. Security researchers from Broadcom's Symantec and Carbon Black divisions identified a previously unknown backdoor—tracked as Backdoor.Turn—that masks malicious traffic as legitimate Teams server connections, allowing attackers to maintain persistence and exfiltrate data while remaining virtually invisible to security tools.
The discovery marks a significant escalation in ransomware tradecraft, demonstrating how threat actors are increasingly leveraging legitimate cloud services to bypass traditional network-based defenses. Experts describe the technique as "exceptionally sophisticated," highlighting a concerning trend where enterprise-grade infrastructure is being weaponized against the organizations it was designed to serve.
## The Threat: Backdoor.Turn
Backdoor.Turn represents a departure from typical ransomware operations. Rather than relying on standard command-and-control infrastructure vulnerable to detection, the backdoor implements an elegant technical solution that routes attacker commands through Microsoft's own Skype-backed identity services and TURN relay servers.
The malware accomplishes this through a multi-step process:
"This appears to be the first malware family to abuse the TURN relay infrastructure in this manner," Symantec and Carbon Black researchers note. The technique is particularly insidious because network monitoring tools observing outbound traffic will log only connections to legitimate Microsoft services, leaving defenders unaware that data is being systematically siphoned away by malicious actors.
The backdoor's capabilities extend far beyond simple persistence. Once deployed, it enables attackers to:
## Attack Timeline and Methodology
The campaign demonstrates remarkable operational discipline and technical sophistication. Initial access to the victim environment—a US services firm—occurred in December 2025, suggesting either exploitation of an unpatched vulnerability or purchase of credentials from an initial access broker.
### Initial Compromise
Researchers assess that the attackers likely gained initial access through an unknown vulnerability in SQL or Microsoft SQL Server (MSSQL). The rapid progression from initial access to ransomware deployment indicates either pre-planning or an access broker scenario where the attacker purchased existing network access rather than conducting their own reconnaissance.
### Persistence and Privilege Escalation
The attackers deployed DLL sideloading attacks to execute code that fetched additional malware from attacker-controlled servers. They then employed a BYOVD (Bring Your Own Vulnerable Driver) strategy—exploiting legitimate vulnerabilities in signed Windows drivers to gain kernel-level access and disable security software.
This approach is particularly effective because:
### Lateral Movement and Data Gathering
Following privilege escalation, the attackers conducted extensive reconnaissance, harvested credentials from compromised systems and browsers, and moved laterally across the network to identify high-value targets and data repositories.
### Encryption and Persistence
The DragonForce ransomware deployed during this final stage encrypted data on the target systems for financial extortion. Simultaneously, Backdoor.Turn was deployed to maintain persistence—ensuring that even if the victim paid the ransom and removed the ransomware, the attackers retained covert access for continued espionage and potential future attacks.
## Technical Architecture: Masquerading as Teams
The technical sophistication of Backdoor.Turn's C&C architecture warrants detailed examination. Traditional ransomware operations use bulletproof hosting providers or compromised servers that security analysts can relatively easily identify and block. By routing communications through Microsoft's legitimate infrastructure, the backdoor bypasses multiple layers of detection:
| Detection Layer | Traditional Approach | Backdoor.Turn |
|---|---|---|
| Network-level blocking | Firewall rules can blacklist known C&C IPs | Impossible to block without disrupting legitimate Teams usage |
| Traffic analysis | Analyst review of network logs identifies suspicious domains | All traffic appears to originate from Microsoft infrastructure |
| DNS monitoring | Suspicious domain lookups are flagged | No suspicious DNS queries |
| HTTPS inspection | SSL certificates reveal C&C domains | SSL certificates are legitimate Microsoft certificates |
This design demonstrates that the attackers understand contemporary security architectures and have engineered their tooling specifically to defeat standard detection mechanisms.
## Background: The Evolution of DragonForce
DragonForce has operated continuously since 2023, evolving from a relatively straightforward ransomware-as-a-service operation into what researchers characterize as a cartel structure with significant resource allocation. The group has demonstrated:
The creation of Backdoor.Turn represents a notable trend in the ransomware landscape: major groups are moving away from off-the-shelf tools toward custom development. This shift indicates either that public exploits have become insufficiently reliable or that sophisticated groups believe custom tools provide competitive advantage in evading detection and attribution.
## Implications for Organizations
This campaign carries several critical implications for enterprise security operations:
Network-centric defense limitations: Organizations that rely primarily on network-based detection for ransomware threats face significant blind spots. An attacker using legitimate cloud infrastructure for C&C achieves effective invisibility to network monitoring tools.
Supply chain risk: The apparent use of an initial access broker or pre-existing vulnerability access suggests that small to mid-sized organizations may face disproportionate risk, as they are more likely targets for access brokers purchasing compromise credentials.
Kernel-level persistence: The BYOVD technique highlights the critical importance of driver security policies and firmware-level protections that validate driver signatures at load time.
Post-encryption access: Organizations accustomed to treating ransomware incidents as discrete events requiring recovery and remediation may face persistent backdoor threats even after paying ransoms or restoring from backups if Backdoor.Turn is not explicitly discovered and removed.
## Recommendations for Defense
Identity and Access Control
Network Monitoring
Incident Response Planning
Vulnerability Management
## HackWire Analysis
The emergence of Backdoor.Turn represents a watershed moment in ransomware evolution—and not just because it's technically clever. What matters is *why* DragonForce built it.
Ransomware groups, contrary to their reputation for brute-force criminality, are actually highly responsive to defender capabilities. When endpoint detection and response (EDR) products became ubiquitous, they developed BYOVD and process-hollowing techniques. When public exploit frameworks were overused and burned, they began developing custom tools. Backdoor.Turn is the logical next step: an acknowledgment that network defense has become sophisticated enough to detect C&C infrastructure, so why not just rent Microsoft's servers?
The timing matters too. This attack occurred in December 2025—suggesting reconnaissance and planning months earlier. Backdoor.Turn wasn't rushed to market; it's a deliberate engineering effort. The fact that it's the first known malware family to abuse TURN relay infrastructure this way suggests either that this technique was discovered during security research and rarely encountered in the wild before this disclosure, or that DragonForce is testing it on carefully selected victims to avoid premature exposure.
Organizations need to stop thinking about ransomware as an encryption problem and start thinking about it as an *access* problem. The actual encryption is often the least consequential phase of these attacks. The real damage occurs during reconnaissance, lateral movement, and credential theft. Backdoor.Turn persists *after* ransomware is deployed, meaning even victims who never decrypt their files can be systematically compromised for weeks or months afterward.
The deeper pattern here deserves attention: cloud services designed with legitimate peer-to-peer scenarios in mind (TURN relays) are being weaponized by actors with enough sophistication to understand their infrastructure at depth. As enterprises migrate more services to the cloud, we should expect more of this kind of lateral thinking from advanced threat actors. The defensive question isn't "how do we block Teams relay servers"—we can't without breaking legitimate communications. The real question is "how do we detect when Teams is being used for purposes it wasn't designed for," and that's a much harder problem.
— HackWire Editorial
## Related Coverage