# Microsoft Teams Servers Weaponized as Backdoor Command Center in Advanced Ransomware Campaign


Symantec researchers discover DragonForce group deploying sophisticated Go-based malware that abuses legitimate Microsoft infrastructure to evade detection


A sophisticated ransomware campaign attributed to the DragonForce group has introduced a novel evasion technique that weaponizes Microsoft Teams infrastructure for command-and-control (C&C) communications. Security researchers from Broadcom's Symantec and Carbon Black divisions identified a previously unknown backdoor—tracked as Backdoor.Turn—that masks malicious traffic as legitimate Teams server connections, allowing attackers to maintain persistence and exfiltrate data while remaining virtually invisible to security tools.


The discovery marks a significant escalation in ransomware tradecraft, demonstrating how threat actors are increasingly leveraging legitimate cloud services to bypass traditional network-based defenses. Experts describe the technique as "exceptionally sophisticated," highlighting a concerning trend where enterprise-grade infrastructure is being weaponized against the organizations it was designed to serve.


## The Threat: Backdoor.Turn


Backdoor.Turn represents a departure from typical ransomware operations. Rather than relying on standard command-and-control infrastructure vulnerable to detection, the backdoor implements an elegant technical solution that routes attacker commands through Microsoft's own Skype-backed identity services and TURN relay servers.


The malware accomplishes this through a multi-step process:


  • Anonymous token acquisition: The backdoor obtains an anonymous Microsoft Teams visitor token from Microsoft's identity infrastructure
  • Legitimate relay abuse: It leverages Microsoft's TURN (Traversal Using Relays around NAT) relay servers—infrastructure designed to facilitate peer-to-peer communications through firewalls
  • Encrypted tunneling: The malware establishes a QUIC (Quick UDP Internet Connection) session to the attacker's actual command server while the Teams infrastructure remains in the visible chain

  • "This appears to be the first malware family to abuse the TURN relay infrastructure in this manner," Symantec and Carbon Black researchers note. The technique is particularly insidious because network monitoring tools observing outbound traffic will log only connections to legitimate Microsoft services, leaving defenders unaware that data is being systematically siphoned away by malicious actors.


    The backdoor's capabilities extend far beyond simple persistence. Once deployed, it enables attackers to:


  • Execute arbitrary commands on compromised systems
  • Create new processes for deploying additional payloads
  • Perform network reconnaissance and scanning
  • Map Active Directory and LDAP structures
  • Conduct lateral movement using harvested credentials
  • Exfiltrate credentials from installed browsers
  • Maintain command channel access for post-ransomware operations

  • ## Attack Timeline and Methodology


    The campaign demonstrates remarkable operational discipline and technical sophistication. Initial access to the victim environment—a US services firm—occurred in December 2025, suggesting either exploitation of an unpatched vulnerability or purchase of credentials from an initial access broker.


    ### Initial Compromise


    Researchers assess that the attackers likely gained initial access through an unknown vulnerability in SQL or Microsoft SQL Server (MSSQL). The rapid progression from initial access to ransomware deployment indicates either pre-planning or an access broker scenario where the attacker purchased existing network access rather than conducting their own reconnaissance.


    ### Persistence and Privilege Escalation


    The attackers deployed DLL sideloading attacks to execute code that fetched additional malware from attacker-controlled servers. They then employed a BYOVD (Bring Your Own Vulnerable Driver) strategy—exploiting legitimate vulnerabilities in signed Windows drivers to gain kernel-level access and disable security software.


    This approach is particularly effective because:


  • Signed drivers appear legitimate to operating system security mechanisms
  • Known vulnerabilities in commercial drivers are well-documented in public databases
  • Kernel-level access allows termination of security processes and EDR agents
  • BYOVD techniques are difficult to detect without specialized driver validation policies

  • ### Lateral Movement and Data Gathering


    Following privilege escalation, the attackers conducted extensive reconnaissance, harvested credentials from compromised systems and browsers, and moved laterally across the network to identify high-value targets and data repositories.


    ### Encryption and Persistence


    The DragonForce ransomware deployed during this final stage encrypted data on the target systems for financial extortion. Simultaneously, Backdoor.Turn was deployed to maintain persistence—ensuring that even if the victim paid the ransom and removed the ransomware, the attackers retained covert access for continued espionage and potential future attacks.


    ## Technical Architecture: Masquerading as Teams


    The technical sophistication of Backdoor.Turn's C&C architecture warrants detailed examination. Traditional ransomware operations use bulletproof hosting providers or compromised servers that security analysts can relatively easily identify and block. By routing communications through Microsoft's legitimate infrastructure, the backdoor bypasses multiple layers of detection:


    | Detection Layer | Traditional Approach | Backdoor.Turn |

    |---|---|---|

    | Network-level blocking | Firewall rules can blacklist known C&C IPs | Impossible to block without disrupting legitimate Teams usage |

    | Traffic analysis | Analyst review of network logs identifies suspicious domains | All traffic appears to originate from Microsoft infrastructure |

    | DNS monitoring | Suspicious domain lookups are flagged | No suspicious DNS queries |

    | HTTPS inspection | SSL certificates reveal C&C domains | SSL certificates are legitimate Microsoft certificates |


    This design demonstrates that the attackers understand contemporary security architectures and have engineered their tooling specifically to defeat standard detection mechanisms.


    ## Background: The Evolution of DragonForce


    DragonForce has operated continuously since 2023, evolving from a relatively straightforward ransomware-as-a-service operation into what researchers characterize as a cartel structure with significant resource allocation. The group has demonstrated:


  • Organized hierarchy: Operating with dedicated roles for initial access, lateral movement, encryption, and victim communication
  • Advanced capabilities: Developing custom tools rather than relying exclusively on publicly available exploit kits
  • Resource investment: The development and deployment of Backdoor.Turn suggests access to experienced software engineers
  • Operational maturity: Long-term planning, sophisticated attack choreography, and coordination across multiple phases

  • The creation of Backdoor.Turn represents a notable trend in the ransomware landscape: major groups are moving away from off-the-shelf tools toward custom development. This shift indicates either that public exploits have become insufficiently reliable or that sophisticated groups believe custom tools provide competitive advantage in evading detection and attribution.


    ## Implications for Organizations


    This campaign carries several critical implications for enterprise security operations:


    Network-centric defense limitations: Organizations that rely primarily on network-based detection for ransomware threats face significant blind spots. An attacker using legitimate cloud infrastructure for C&C achieves effective invisibility to network monitoring tools.


    Supply chain risk: The apparent use of an initial access broker or pre-existing vulnerability access suggests that small to mid-sized organizations may face disproportionate risk, as they are more likely targets for access brokers purchasing compromise credentials.


    Kernel-level persistence: The BYOVD technique highlights the critical importance of driver security policies and firmware-level protections that validate driver signatures at load time.


    Post-encryption access: Organizations accustomed to treating ransomware incidents as discrete events requiring recovery and remediation may face persistent backdoor threats even after paying ransoms or restoring from backups if Backdoor.Turn is not explicitly discovered and removed.


    ## Recommendations for Defense


    Identity and Access Control

  • Implement multi-factor authentication across all administrative accounts
  • Monitor Teams and other cloud services for suspicious login patterns and anonymous token generation
  • Review and restrict Teams guest access policies

  • Network Monitoring

  • Implement endpoint-to-cloud network monitoring that can detect patterns consistent with QUIC tunneling abuse
  • Maintain detailed logs of Teams API authentication and token requests
  • Review and validate driver loading policies to prevent BYOVD attacks

  • Incident Response Planning

  • Assume ransomware attacks may involve persistent backdoors; do not consider incidents closed after ransom payment or backup restoration
  • Conduct forensic analysis specifically targeting custom malware and persistence mechanisms
  • Engage threat intelligence firms for indicators of compromise specific to Backdoor.Turn

  • Vulnerability Management

  • Prioritize patching of SQL Server and MSSQL vulnerabilities
  • Maintain inventory of drivers vulnerable to BYOVD exploitation and implement restrictions on loading
  • Conduct regular security assessments of internet-facing SQL database instances

  • ## HackWire Analysis


    The emergence of Backdoor.Turn represents a watershed moment in ransomware evolution—and not just because it's technically clever. What matters is *why* DragonForce built it.


    Ransomware groups, contrary to their reputation for brute-force criminality, are actually highly responsive to defender capabilities. When endpoint detection and response (EDR) products became ubiquitous, they developed BYOVD and process-hollowing techniques. When public exploit frameworks were overused and burned, they began developing custom tools. Backdoor.Turn is the logical next step: an acknowledgment that network defense has become sophisticated enough to detect C&C infrastructure, so why not just rent Microsoft's servers?


    The timing matters too. This attack occurred in December 2025—suggesting reconnaissance and planning months earlier. Backdoor.Turn wasn't rushed to market; it's a deliberate engineering effort. The fact that it's the first known malware family to abuse TURN relay infrastructure this way suggests either that this technique was discovered during security research and rarely encountered in the wild before this disclosure, or that DragonForce is testing it on carefully selected victims to avoid premature exposure.


    Organizations need to stop thinking about ransomware as an encryption problem and start thinking about it as an *access* problem. The actual encryption is often the least consequential phase of these attacks. The real damage occurs during reconnaissance, lateral movement, and credential theft. Backdoor.Turn persists *after* ransomware is deployed, meaning even victims who never decrypt their files can be systematically compromised for weeks or months afterward.


    The deeper pattern here deserves attention: cloud services designed with legitimate peer-to-peer scenarios in mind (TURN relays) are being weaponized by actors with enough sophistication to understand their infrastructure at depth. As enterprises migrate more services to the cloud, we should expect more of this kind of lateral thinking from advanced threat actors. The defensive question isn't "how do we block Teams relay servers"—we can't without breaking legitimate communications. The real question is "how do we detect when Teams is being used for purposes it wasn't designed for," and that's a much harder problem.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)