DragonForce hides command channel inside Microsoft Teams relay servers with new Backdoor.Turn malware
Security teams that wave through Microsoft Teams $MSFT traffic now have reason to look closer. Symantec says the DragonForce ransomware crew hid its command channel inside Microsoft's legitimate Teams relay servers using a new Go backdoor, Backdoor.Turn, the first malware known t
Defenders who treat Microsoft Teams $MSFT traffic as inherently safe now face a harder problem. According to Symantec and Carbon Black, operators of the DragonForce ransomware group concealed their command-and-control channel inside Microsoft's own Teams relay infrastructure during an intrusion at a major U.S. services company. The tool behind it, a Go-based backdoor named Backdoor.Turn, is the first known malware to abuse Microsoft Teams TURN relay servers for this purpose. The technique matters because it hides malicious traffic where defenders rarely look. Backdoor.Turn obtained an anonymous Teams visitor token from Microsoft's Skype-backed identity services, then routed its communications through a legitimate Microsoft TURN relay using the QUIC transport protocol. To a network monitor, the connection resembles ordinary Teams activity. Once active, the backdoor can run commands, scan networks, search Active Directory and LDAP environments, move laterally with stolen credentials, and harvest browser passwords. The intrusion did not happen overnight. Symantec reports the attackers first accessed the victim network in December 2025, used DLL sideloading to fetch additional payloads, and exploited a previously undocumented flaw in a Huawei driver to mask their activity. DragonForce operates as a ransomware-as-a-service business, supplying affiliates with tooling and infrastructure in exchange for a share of any ransom paid. Symantec and Carbon Black have published indicators of compromise tied to the campaign.