A sophisticated ransomware campaign has turned Microsoft’s own collaboration infrastructure against defenders, with attackers concealing command-and-control traffic inside Microsoft Teams’ relay servers, marking the first known exploitation of TURN relay technology for malware communications in the wild.
Symantec Team, who investigated and attributed the intrusion, noted that initial access was likely gained through a vulnerability in an SQL or MSSQL server, though the attackers may have alternatively purchased access from an initial access broker.
The threat actor behind the DragonForce ransomware targeted a major U.S. services firm, maintaining an undetected presence on the victim’s network for 1 to 2 months beginning in December 2025.
Once inside, the attackers deployed a .zip archive containing a legitimate VirtualBox/DbgView executable paired with a malicious DLL designed for side-loading.
Microsoft Teams Relay to hide malware Traffic
The malicious vboxrt.dll downloaded secondary payloads from remote servers, enabling reconnaissance, persistence, and defense evasion across the compromised environment, Symantec said.
Attackers further solidified their foothold by modifying firewall rules, creating new user accounts, and enabling LimitBlankPassword access to compromised machines.
The most technically significant component of this campaign is Backdoor.Turn, a custom Go-based remote access trojan (RAT) injected into the legitimate DbgView64.exe process for stealth.

Its C2 mechanism is inspired by the “Ghost Calls” technique presented at Black Hat 2025, engineered specifically to make malicious traffic indistinguishable from normal Microsoft Teams activity.
The backdoor first requests an anonymous visitor token from Microsoft’s Teams/Skype identity backend. It then uses a legitimate Microsoft TURN relay server to establish the initial connection before opening a direct QUIC session to the attacker’s actual C2 server.
To network defenders, all outbound traffic appears to terminate at legitimate Microsoft Teams servers, rendering traditional network-based detection completely ineffective. Beyond communication tunneling, Backdoor.
Turn supports command execution, network scanning with TLS certificate harvesting, LDAP and Active Directory domain mapping, credential-based lateral movement, and browser credential theft from compromised endpoints.
The attackers deployed an unusually broad set of Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint security at the kernel level.
The most notable is the Havoc Process Terminator, a novel exploitation of Huawei’s HWAuidoOs2Ec.sys driver that was not publicly known to be vulnerable at the time of the attack, though Huntress documented its exploitable status in March 2026, after this intrusion had already occurred.
The attackers also abused CVE-2023-52271 in Topaz Antifraud’s wsftprm.sys, CVE-2025-61155 in Tower of Fantasy’s Gamedriverx64.sys, and CVE-2025-1055 in K7 Security’s K7RKScan.sys.
Adding further complexity, the group deployed Abyss Worker, a custom malicious driver masquerading as a legitimate Palo Alto driver.
Symantec stated that traditional BYOVD attacks exploit weaknesses in legitimate signed drivers; this is a purpose-built malicious driver, a technique rarely observed in ransomware operations.
DragonForce, active since at least June 2023 and tracked by Symantec under the threat cluster Hackledorb, has evolved from a standard ransomware-as-a-service (RaaS) operation into a highly structured cartel model.
The deployment of Backdoor.Turn alongside multi-vector BYOVD evasion represents a significant leap in operational capability, and exploiting a driver with no prior public vulnerability record demonstrates the group’s investment in developing novel offensive tradecraft.
This operational profile positions DragonForce among the most technically capable and persistent ransomware groups active today.
| Indicator | Type | Description |
|---|---|---|
821da79d727351dd67ce5df7950e9a3de6647a3cf474bb3a093f67507fed92a6 | SHA-256 | Backdoor.Turn |
048e18416177de2ead251abdf4d89837f6807c6aba4d5b1debe49adfdecbf05c | SHA-256 | Backdoor.Turn (secondary sample) |
e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22 | SHA-256 | DragonForce ransomware payload |
ce66b8221446c9b6d83f0ce6382f430e519601641e5daaaf1ca7a8a8806cb0b0 | SHA-256 | Shellcode containing Backdoor.Turn |
8a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c5531 | SHA-256 | Havoc Process Terminator |
8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2 | SHA-256 | ABYSSWORKER malicious driver |
82b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013b | SHA-256 | Downloader (initial stage) |
f174c19902523dcf005fa044b6598403a5e5c0a5982398d1bc0dcc5ec1cd351b | SHA-256 | Sideloaded DLL mimicking VirtualBox |
62.164.177[.]25 | IP Address | Backdoor.Turn C&C server |
http://192.36.27[.]51/TechSupV18Fix3.zip | URL | Malicious ZIP archive download URL |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.