EPISODE · Jun 17, 2026 · 0 MIN
Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
from Security Stuff · host Trace3
The DragonForce ransomware group has deployed a sophisticated new backdoor that disguises its malicious traffic as legitimate Microsoft Teams communications, marking the first known malware to abuse Microsoft's TURN relay infrastructure in this way. The custom malware, called Backdoor.Turn, obtains anonymous Teams tokens and uses legitimate Microsoft relay servers to communicate with attacker command-and-control servers, making it nearly impossible for security tools to distinguish malicious activity from normal Teams traffic. The backdoor was used in a December attack on a US services firm where hackers gained kernel-level access, terminated security processes, and maintained persistent access even after deploying ransomware for data encryption and theft.
Embed this episode
What this episode covers
The DragonForce ransomware group has deployed a sophisticated new backdoor that disguises its malicious traffic as legitimate Microsoft Teams communications, marking the first known malware to abuse Microsoft's TURN relay infrastructure in this way. The custom malware, called Backdoor.Turn, obtains anonymous Teams tokens and uses legitimate Microsoft relay servers to communicate with attacker command-and-control servers, making it nearly impossible for security tools to distinguish malicious ...
NOW PLAYING
Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.