# Ransomware Gang Weaponizes Microsoft Teams Infrastructure to Hide C2 Communications
DragonForce operators deploy first in-the-wild malware abusing Teams TURN relays, marking a significant escalation in evasion tactics
The DragonForce ransomware operation has escalated its tradecraft by deploying sophisticated malware that weaponizes Microsoft Teams' relay infrastructure to mask command-and-control communications, researchers at Symantec revealed this week. The custom backdoor, dubbed Backdoor.Turn, represents the first known instance of malware exploiting Teams' TURN protocol in active attacks—a technique that academics demonstrated last year but criminals have now weaponized at scale.
The attack, observed in December 2025 against a major U.S. services company, showcases how ransomware operators are adapting to evade modern detection systems by hiding malicious traffic within the legitimate, encrypted communications of trusted enterprise software.
## The Threat: A New Evasion Frontier
Backdoor.Turn is a Go-based remote access trojan (RAT) with a critical innovation: it routes command-and-control traffic through Microsoft Teams' own relay infrastructure, making malicious communications appear identical to legitimate Teams traffic. This approach exploits the Traversal Using Relays around NAT (TURN) protocol—a standard component of Teams that allows clients behind firewalls or on private networks to maintain connectivity when direct connections are unavailable.
By obtaining an anonymous Teams visitor token and leveraging Microsoft's legitimate TURN relay servers, the backdoor establishes a covert channel that blends seamlessly with normal enterprise communications. Security teams monitoring network traffic see only encrypted Teams data, while attackers maintain full remote access to compromised systems.
Backdoor.Turn capabilities include:
The malware was discovered injected into DbgView64.exe, a legitimate Windows debugging utility, suggesting the attackers planned to maintain persistence or establish backup access mechanisms for future intrusions.
## How the Attack Unfolds: Multi-Stage Sophistication
The December 2025 attack Symantec investigated reveals the meticulous staging and evasion tactics characteristic of enterprise-grade ransomware operations:
Stage 1: Initial Access
Stage 2: Persistence and Privilege Escalation
LimitBlankPassword security policy to enable passwordless logonsStage 3: Defense Evasion (BYOVD - Bring Your Own Vulnerable Driver)
The attackers deployed multiple vulnerable drivers to achieve kernel-level access and terminate security tools:
| Driver | CVE/Name | Purpose |
|--------|----------|---------|
| Huawei HWAuidoOs2Ec.sys | "Havoc Process Terminator" | Kill security processes |
| Topaz wsftprm.sys | CVE-2023-52271 | Privilege escalation |
| Tower of Fantasy GameDriverx64.sys | CVE-2025-61155 | Kernel access |
| K7 Security K7RKScan.sys | CVE-2025-1055 | EDR/AV bypass |
| ABYSSWORKER | Custom malicious driver | Masquerade as Palo Alto component |
Stage 4: Reconnaissance and Data Theft
Stage 5: Encryption and Extortion
## Background and Context: From Theory to Practice
This attack builds directly on academic research published by Praetorian in 2025, which introduced the "Ghost Calls" technique. Researchers demonstrated that temporary TURN credentials issued by Teams and Zoom could be hijacked to create stealthy tunnels through trusted conferencing infrastructure. While Ghost Calls was a proof-of-concept, Backdoor.Turn is the first known production malware to weaponize the same approach.
DragonForce itself emerged as a notable threat actor around 2023, distinguishing itself through a cartel-style organizational structure more common in organized cybercrime than traditional APT groups. The operation has been linked to Scattered Spider, the same threat group behind high-profile breaches including the 2023 MGM Resorts compromise. This connection underscores that DragonForce operators possess sophisticated attack capabilities and established relationships within criminal ecosystems.
The use of BYOVD techniques further reflects the professionalization of ransomware operations. Rather than developing zero-day exploits, attackers now routinely abuse legitimate but vulnerable drivers signed by major technology vendors—a tactic that bypasses driver signature enforcement while requiring minimal technical innovation.
## Implications for Defenders
Microsoft's Trusted Network Problem
Teams TURN relay abuse exposes a fundamental challenge in modern security architecture: legitimate, encrypted communications from trusted enterprise software provide cover for malicious activity. Detection becomes nearly impossible when attackers hide inside the very infrastructure designed to enable secure, remote work. Organizations cannot simply block Teams traffic without disrupting business operations.
The Convergence of Old and New Threats
This attack combines well-established techniques (SQL injection, DLL sideloading, BYOVD) with cutting-edge evasion (TURN relay abuse), demonstrating that ransomware operators no longer need novel zero-days to succeed. Sophisticated tradecraft beats complexity.
TURN Protocol Risks Extend Beyond Teams
While this attack targeted Teams infrastructure, the underlying TURN protocol is used by multiple conferencing and communication platforms. Organizations should assume that similar attacks against Zoom, Slack, or other TURN-dependent services may emerge.
## Recommendations for Organizations
- Patch all SQL Server instances immediately; assume unpatched servers will be exploited
- Review and remove rogue user accounts created in recent weeks
- Scan for vulnerable drivers on all systems (K7RKScan, GameDriver, wsftprm, HWAuidoOs2Ec)
- Implement strict firewall egress rules; block unusual outbound connections from non-network services
- Monitor for Backdoor.Turn IoCs published by Symantec
- Alert on DLL sideloading attempts using legitimate Windows utilities
- Implement application whitelisting for critical processes
- Monitor for Anonymous Teams visitor token generation followed by outbound connections
- Enforce kernel driver signing verification; audit installed drivers quarterly
- Implement network segmentation to isolate critical databases
- Require multi-factor authentication on all administrative accounts
- Deploy EDR/XDR solutions with kernel-level visibility to detect driver-based evasion
---
## HackWire Analysis
The Death of Detection by Signature
This attack illustrates a harsh truth: defenders cannot win by signature-matching alone. Backdoor.Turn hiding in Teams traffic isn't a novel vulnerability—it's a purposeful misuse of legitimate infrastructure. Symantec's research is thorough, and threat intel sharing is improving, but by the time indicators of compromise reach organizations, the backdoor's C2 channel has already adapted.
The real lesson is about layering and segmentation. DragonForce succeeded because they were able to move from database foothold → kernel access → domain enumeration → exfiltration seamlessly. Each stage should have been a friction point. Instead, weak SQL configurations, unpatched drivers, and flat network architecture created a highway from initial access to data theft.
The TURN relay abuse itself is almost secondary. Yes, it's clever—and yes, it will spawn copy-cat variants. But the actor didn't need it to evade defenders; they used it because it *works*. Organizations that can't detect a database compromise or spot unusual privilege escalation patterns won't catch this attack regardless of whether C2 traffic travels over TURN relays or direct HTTP.
What should worry defenders most: this attack is *teachable*. Praetorian published Ghost Calls last year. Symantec just published full IoCs. The BYOVD techniques are documented. Within months, mid-tier ransomware operators will be running variants of this playbook. The window for hardening is now.
— HackWire Editorial
---
## Related Coverage