Critical Microsoft Teams Flaw Lets Attackers Hide Malware Traffic
Key Takeaways A new Go-based remote access Trojan (RAT), Backdoor.TURN, is exploiting Microsoft Teams infrastructure to mask command-and-control (C2) traffic. The malware leverages Teams TURN relay...
Key Takeaways
- A new Go-based remote access Trojan (RAT), Backdoor.TURN, is exploiting Microsoft Teams infrastructure to mask command-and-control (C2) traffic.
- The malware leverages Teams TURN relay servers, making malicious communications appear as legitimate enterprise activity.
- This sophisticated attack campaign, linked to DragonForce ransomware, allowed attackers to remain undetected for up to two months within a major U.S. services firm.
- The technique, while inspired by prior research, marks the first documented real-world exploitation of Microsoft Teams TURN relay servers for covert C2.
Cyber adversaries are increasingly leveraging legitimate cloud services to conceal their nefarious activities. A recently uncovered campaign reveals a sophisticated method where threat actors weaponized Microsoft Teams infrastructure to hide malicious traffic, effectively blending it with normal enterprise communications.
Table Of Content
Analysis by the Symantec Threat Hunter Team details a novel Go-based remote access Trojan (RAT) dubbed Backdoor.TURN. This malware exploits Microsoft Teams TURN relay servers to obfuscate its command-and-control (C2) communications, making them indistinguishable from standard outbound Teams traffic.
This particular campaign is associated with a DragonForce ransomware attack that targeted a prominent U.S. services company. The attackers managed to maintain a stealthy presence within the victim’s network for an extended period, reportedly up to two months, before detection.
Instead of direct communication with attacker-controlled servers, Backdoor.TURN reroutes its traffic through Microsoft’s own servers. This critical evasion technique ensures that network monitoring tools perceive these connections as legitimate interactions with Microsoft Teams services, thereby bypassing detection.
The operational mechanism of Backdoor.TURN involves requesting an anonymous visitor token from Microsoft’s identity services, which are backed by Skype infrastructure.
Hackers Weaponize Microsoft Teams
Symantec researchers elaborated that the malware utilizes this obtained token to authenticate with the Teams infrastructure, subsequently establishing a relay session via TURN servers. Once this connection is secured, it initiates a QUIC session with the actual C2 server. This ingenious method ensures that network defenders only observe traffic directed to legitimate Microsoft domains, effectively obscuring the malicious intent.
While the precise initial access vector for this intrusion remains unconfirmed, Symantec’s analysis suggests that the attackers likely exploited an undisclosed SQL or MSSQL server vulnerability, or gained access through an initial access broker.
The intrusion commenced in December 2025. Following initial access, the attackers deployed a malicious ZIP archive containing a legitimate VirtualBox executable alongside a weaponized DLL. Through DLL sideloading, the malicious code was executed under a trusted process, establishing persistent and stealthy access. Post-execution, the threat actors engaged in comprehensive reconnaissance, harvested credentials, and executed lateral movement across the compromised network.
To ensure prolonged access and resilience, the attackers modified firewall rules, created additional user accounts, and adjusted system settings. Symantec noted that these actions were meticulously designed to maintain uninterrupted C2 communication.
A significant aspect of this campaign is its advanced defense evasion strategy. The attackers employed a Bring Your Own Vulnerable Driver (BYOVD) technique to disable security tools at the kernel level. Notably, Symantec researchers observed a novel exploitation of the Huawei driver HWAuidoOs2Ec.sys, which they described as a “Havoc Process Terminator.”
Additional drivers associated with CVE-2023-52271, CVE-2025-61155, and CVE-2025-1055 were also reportedly abused. Furthermore, the attackers deployed a custom malicious driver, named Abyss Worker, which was disguised as a legitimate Palo Alto driver, specifically to terminate security processes.
The Backdoor.TURN payload was injected into the legitimate DbgView64.exe process and deployed after the execution of the ransomware. According to the Symantec Threat Hunter Team, this timing suggests that the malware may serve purposes beyond the immediate ransomware attack, such as maintaining persistence or enabling future access, potentially for resale to other threat actors.
The Backdoor supports a wide array of capabilities, including remote command execution, Active Directory enumeration, network scanning, credential theft, and lateral movement.
This sophisticated technique draws inspiration from the “Ghost Calls” research presented at Black Hat 2025, which demonstrated the theoretical potential for abusing web conferencing platforms for covert communication. However, Symantec emphasized that this marks the first documented real-world instance of Microsoft Teams TURN relay infrastructure being exploited in such a manner.
DragonForce, a threat group active since 2023 and tracked by Symantec as Hackledorb, has evolved into a highly structured and sophisticated entity. Its adoption of trusted cloud infrastructure combined with innovative exploitation techniques underscores a growing and concerning trend in contemporary cyberattacks.
As highlighted by the Symantec Threat Hunter Team, the practice of blending malicious traffic with legitimate services significantly diminishes the visibility of network defenders. This necessitates a greater reliance on behavioral detection mechanisms and the implementation of more stringent controls over vulnerable drivers and enterprise communication platforms.
What You Should Do
- Implement robust behavioral detection systems to identify anomalous activity within legitimate traffic flows.
- Enforce strict controls and monitoring over all drivers, particularly vulnerable ones, and consider driver integrity checks.
- Review and strengthen security policies for enterprise communication platforms like Microsoft Teams, including monitoring for unusual authentication requests or relay usage.
- Regularly audit and update firewall rules and user account privileges to prevent unauthorized modifications.
- Ensure all security software and operating systems are kept up-to-date with the latest patches to mitigate known vulnerabilities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.