DragonForce Hackers' Stealthy Microsoft Teams Backdoor Revealed! (2026)

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic: A Deep Dive into the Threat Landscape

The recent discovery of DragonForce hackers exploiting Microsoft Teams relays to conceal their command-and-control (C2) traffic has raised significant concerns in the cybersecurity community. This sophisticated attack technique showcases the evolving tactics employed by threat actors, highlighting the need for constant vigilance and adaptation in the realm of cybersecurity.

The Attack Unveiled

The threat actors, associated with the DragonForce ransomware group, have been observed deploying a custom Go-based remote access trojan (RAT) named Backdoor.Turn. This backdoor is designed to seamlessly integrate into the Microsoft Teams relay infrastructure, allowing attackers to establish covert communication channels without raising suspicion.

By obtaining an anonymous Teams visitor token from Microsoft's Skype-backed identity services, Backdoor.Turn leverages a legitimate Microsoft TURN relay to set up the connection. This relay-assisted setup enables the malware to establish a direct QUIC session to the attacker's C2 server, all while appearing as legitimate outbound connections to Microsoft Teams servers.

The Impact and Implications

The implications of this attack are far-reaching. By remaining undetected for one to two months within the victim network, the attackers were able to conduct reconnaissance, establish persistence, and silence security software using a Huawei driver (HWAuidoOs2Ec.sys). This level of stealth and persistence underscores the sophistication of the threat actors and their ability to adapt and evolve their tactics.

The use of the BYOVD (Bring Your Own Vulnerable Driver) technique further emphasizes the attackers' resourcefulness. By injecting Backdoor.Turn into the legitimate DbgView64.exe process, the attackers ensure continued access to the compromised host, potentially for future attacks or reselling purposes.

A Complex Web of Vulnerabilities

The attack chain begins with the threat actors obtaining initial access through a vulnerability in either an SQL or MS-SQL server. The exact nature of the flaw remains unknown, but the possibility of exploitation through an initial access broker (IAB) cannot be ruled out. This initial access is then leveraged to deliver a ZIP archive, which, under the guise of a tech support hotfix, launches a DLL side-loading attack.

The DLL side-loading attack, in turn, triggers the execution of the rogue DLL, which conducts reconnaissance, sets up persistence, and silences security software using the Huawei driver. This multi-vector approach showcases the attackers' ability to exploit multiple vulnerabilities and maintain a persistent presence within the victim network.

The Broader Threat Landscape

The DragonForce group's shift from a conventional ransomware-as-a-service (RaaS) model to a highly organized, formalized cartel structure is particularly concerning. This evolution in their operational model indicates a more structured and sophisticated approach to cybercrime, with a focus on continuous capability development and the adoption of advanced techniques.

The deployment of Backdoor.Turn, combined with their multi-vector BYOVD evasion, positions DragonForce as one of the most capable and persistent ransomware groups operating today. This development underscores the need for organizations to remain vigilant and proactive in their cybersecurity defenses, adapting to the ever-evolving threat landscape.

Conclusion: A Call to Action

The abuse of Microsoft Teams relays by DragonForce hackers highlights the importance of staying ahead of the curve in cybersecurity. As threat actors continue to refine their tactics and exploit vulnerabilities, organizations must invest in robust security measures, regular vulnerability assessments, and comprehensive training programs to ensure they are prepared for the challenges that lie ahead.

DragonForce Hackers' Stealthy Microsoft Teams Backdoor Revealed! (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Trent Wehner

Last Updated:

Views: 5870

Rating: 4.6 / 5 (56 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Trent Wehner

Birthday: 1993-03-14

Address: 872 Kevin Squares, New Codyville, AK 01785-0416

Phone: +18698800304764

Job: Senior Farming Developer

Hobby: Paintball, Calligraphy, Hunting, Flying disc, Lapidary, Rafting, Inline skating

Introduction: My name is Trent Wehner, I am a talented, brainy, zealous, light, funny, gleaming, attractive person who loves writing and wants to share my knowledge and understanding with you.