Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical FortiGate RCE CVE-2022-42475 Exploited in Polish Energy Sector Attack
August 11, 2026
GhostJacking Attack Hijacks AI Agents to Run Malicious Code on Developer Machines
August 11, 2026
Horizon3.ai Secures $20M to Boost Partner-Led Growth and Ecosystem
August 11, 2026
Home/CyberSecurity News/Critical Microsoft Teams Flaw Lets Attackers Hide Malware Traffic
CyberSecurity News

Critical Microsoft Teams Flaw Lets Attackers Hide Malware Traffic

Key Takeaways A new Go-based remote access Trojan (RAT), Backdoor.TURN, is exploiting Microsoft Teams infrastructure to mask command-and-control (C2) traffic. The malware leverages Teams TURN relay...

Sarah simpson
Sarah simpson
June 16, 2026 4 Min Read
44 0

Key Takeaways

  • A new Go-based remote access Trojan (RAT), Backdoor.TURN, is exploiting Microsoft Teams infrastructure to mask command-and-control (C2) traffic.
  • The malware leverages Teams TURN relay servers, making malicious communications appear as legitimate enterprise activity.
  • This sophisticated attack campaign, linked to DragonForce ransomware, allowed attackers to remain undetected for up to two months within a major U.S. services firm.
  • The technique, while inspired by prior research, marks the first documented real-world exploitation of Microsoft Teams TURN relay servers for covert C2.

Cyber adversaries are increasingly leveraging legitimate cloud services to conceal their nefarious activities. A recently uncovered campaign reveals a sophisticated method where threat actors weaponized Microsoft Teams infrastructure to hide malicious traffic, effectively blending it with normal enterprise communications.

Table Of Content

  • Key Takeaways
  • Hackers Weaponize Microsoft Teams
  • What You Should Do

Analysis by the Symantec Threat Hunter Team details a novel Go-based remote access Trojan (RAT) dubbed Backdoor.TURN. This malware exploits Microsoft Teams TURN relay servers to obfuscate its command-and-control (C2) communications, making them indistinguishable from standard outbound Teams traffic.

This particular campaign is associated with a DragonForce ransomware attack that targeted a prominent U.S. services company. The attackers managed to maintain a stealthy presence within the victim’s network for an extended period, reportedly up to two months, before detection.

Instead of direct communication with attacker-controlled servers, Backdoor.TURN reroutes its traffic through Microsoft’s own servers. This critical evasion technique ensures that network monitoring tools perceive these connections as legitimate interactions with Microsoft Teams services, thereby bypassing detection.

The operational mechanism of Backdoor.TURN involves requesting an anonymous visitor token from Microsoft’s identity services, which are backed by Skype infrastructure.

Hackers Weaponize Microsoft Teams

Symantec researchers elaborated that the malware utilizes this obtained token to authenticate with the Teams infrastructure, subsequently establishing a relay session via TURN servers. Once this connection is secured, it initiates a QUIC session with the actual C2 server. This ingenious method ensures that network defenders only observe traffic directed to legitimate Microsoft domains, effectively obscuring the malicious intent.

While the precise initial access vector for this intrusion remains unconfirmed, Symantec’s analysis suggests that the attackers likely exploited an undisclosed SQL or MSSQL server vulnerability, or gained access through an initial access broker.

The intrusion commenced in December 2025. Following initial access, the attackers deployed a malicious ZIP archive containing a legitimate VirtualBox executable alongside a weaponized DLL. Through DLL sideloading, the malicious code was executed under a trusted process, establishing persistent and stealthy access. Post-execution, the threat actors engaged in comprehensive reconnaissance, harvested credentials, and executed lateral movement across the compromised network.

To ensure prolonged access and resilience, the attackers modified firewall rules, created additional user accounts, and adjusted system settings. Symantec noted that these actions were meticulously designed to maintain uninterrupted C2 communication.

A significant aspect of this campaign is its advanced defense evasion strategy. The attackers employed a Bring Your Own Vulnerable Driver (BYOVD) technique to disable security tools at the kernel level. Notably, Symantec researchers observed a novel exploitation of the Huawei driver HWAuidoOs2Ec.sys, which they described as a “Havoc Process Terminator.”

Additional drivers associated with CVE-2023-52271, CVE-2025-61155, and CVE-2025-1055 were also reportedly abused. Furthermore, the attackers deployed a custom malicious driver, named Abyss Worker, which was disguised as a legitimate Palo Alto driver, specifically to terminate security processes.

The Backdoor.TURN payload was injected into the legitimate DbgView64.exe process and deployed after the execution of the ransomware. According to the Symantec Threat Hunter Team, this timing suggests that the malware may serve purposes beyond the immediate ransomware attack, such as maintaining persistence or enabling future access, potentially for resale to other threat actors.

The Backdoor supports a wide array of capabilities, including remote command execution, Active Directory enumeration, network scanning, credential theft, and lateral movement.

This sophisticated technique draws inspiration from the “Ghost Calls” research presented at Black Hat 2025, which demonstrated the theoretical potential for abusing web conferencing platforms for covert communication. However, Symantec emphasized that this marks the first documented real-world instance of Microsoft Teams TURN relay infrastructure being exploited in such a manner.

DragonForce, a threat group active since 2023 and tracked by Symantec as Hackledorb, has evolved into a highly structured and sophisticated entity. Its adoption of trusted cloud infrastructure combined with innovative exploitation techniques underscores a growing and concerning trend in contemporary cyberattacks.

As highlighted by the Symantec Threat Hunter Team, the practice of blending malicious traffic with legitimate services significantly diminishes the visibility of network defenders. This necessitates a greater reliance on behavioral detection mechanisms and the implementation of more stringent controls over vulnerable drivers and enterprise communication platforms.

What You Should Do

  • Implement robust behavioral detection systems to identify anomalous activity within legitimate traffic flows.
  • Enforce strict controls and monitoring over all drivers, particularly vulnerable ones, and consider driver integrity checks.
  • Review and strengthen security policies for enterprise communication platforms like Microsoft Teams, including monitoring for unusual authentication requests or relay usage.
  • Regularly audit and update firewall rules and user account privileges to prevent unauthorized modifications.
  • Ensure all security software and operating systems are kept up-to-date with the latest patches to mitigate known vulnerabilities.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitHackerMalwareransomwareSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Interlock and Rhysida Ransomware Groups Share Supper Backdoor

Next Post

Microsoft 365 Device Code Phishing Bypasses MFA for Account Takeover

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Critical SonicWall SMA 1000 Zero-Days Exploited in Ransomware Attacks
August 11, 2026
Critical VMware vCenter CVE-2023-34048 Under Active Exploitation
August 11, 2026
Critical ClamAV Vulnerabilities Let Attackers Trigger DoS
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us