Microsoft Teams Relay Abused to Stealthily Route Malware Communications

A sophisticated ransomware campaign has turned Microsoft’s own collaboration infrastructure against defenders, with attackers concealing command-and-control traffic inside Microsoft Teams’ relay servers, marking the first known exploitation of TURN relay technology for malware communications in the wild.

Symantec Team, who investigated and attributed the intrusion, noted that initial access was likely gained through a vulnerability in an SQL or MSSQL server, though the attackers may have alternatively purchased access from an initial access broker.

The threat actor behind the DragonForce ransomware targeted a major U.S. services firm, maintaining an undetected presence on the victim’s network for 1 to 2 months beginning in December 2025.

Once inside, the attackers deployed a .zip archive containing a legitimate VirtualBox/DbgView executable paired with a malicious DLL designed for side-loading.

Microsoft Teams Relay to hide malware Traffic

The malicious vboxrt.dll downloaded secondary payloads from remote servers, enabling reconnaissance, persistence, and defense evasion across the compromised environment, Symantec said.

Attackers further solidified their foothold by modifying firewall rules, creating new user accounts, and enabling LimitBlankPassword access to compromised machines.

The most technically significant component of this campaign is Backdoor.Turn, a custom Go-based remote access trojan (RAT) injected into the legitimate DbgView64.exe process for stealth.

Attack chain
Attack chain (Source: Security[.]com)

Its C2 mechanism is inspired by the “Ghost Calls” technique presented at Black Hat 2025, engineered specifically to make malicious traffic indistinguishable from normal Microsoft Teams activity.

The backdoor first requests an anonymous visitor token from Microsoft’s Teams/Skype identity backend. It then uses a legitimate Microsoft TURN relay server to establish the initial connection before opening a direct QUIC session to the attacker’s actual C2 server.

To network defenders, all outbound traffic appears to terminate at legitimate Microsoft Teams servers, rendering traditional network-based detection completely ineffective. Beyond communication tunneling, Backdoor.

Turn supports command execution, network scanning with TLS certificate harvesting, LDAP and Active Directory domain mapping, credential-based lateral movement, and browser credential theft from compromised endpoints.

The attackers deployed an unusually broad set of Bring Your Own Vulnerable Driver (BYOVD) techniques to disable endpoint security at the kernel level.

The most notable is the Havoc Process Terminator, a novel exploitation of Huawei’s HWAuidoOs2Ec.sys driver that was not publicly known to be vulnerable at the time of the attack, though Huntress documented its exploitable status in March 2026, after this intrusion had already occurred.

The attackers also abused CVE-2023-52271 in Topaz Antifraud’s wsftprm.sys, CVE-2025-61155 in Tower of Fantasy’s Gamedriverx64.sys, and CVE-2025-1055 in K7 Security’s K7RKScan.sys.

Adding further complexity, the group deployed Abyss Worker, a custom malicious driver masquerading as a legitimate Palo Alto driver.

Symantec stated that traditional BYOVD attacks exploit weaknesses in legitimate signed drivers; this is a purpose-built malicious driver, a technique rarely observed in ransomware operations.

DragonForce, active since at least June 2023 and tracked by Symantec under the threat cluster Hackledorb, has evolved from a standard ransomware-as-a-service (RaaS) operation into a highly structured cartel model.

The deployment of Backdoor.Turn alongside multi-vector BYOVD evasion represents a significant leap in operational capability, and exploiting a driver with no prior public vulnerability record demonstrates the group’s investment in developing novel offensive tradecraft.

This operational profile positions DragonForce among the most technically capable and persistent ransomware groups active today.

IndicatorTypeDescription
821da79d727351dd67ce5df7950e9a3de6647a3cf474bb3a093f67507fed92a6SHA-256Backdoor.Turn
048e18416177de2ead251abdf4d89837f6807c6aba4d5b1debe49adfdecbf05cSHA-256Backdoor.Turn (secondary sample)
e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22SHA-256DragonForce ransomware payload
ce66b8221446c9b6d83f0ce6382f430e519601641e5daaaf1ca7a8a8806cb0b0SHA-256Shellcode containing Backdoor.Turn
8a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c5531SHA-256Havoc Process Terminator
8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2SHA-256ABYSSWORKER malicious driver
82b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013bSHA-256Downloader (initial stage)
f174c19902523dcf005fa044b6598403a5e5c0a5982398d1bc0dcc5ec1cd351bSHA-256Sideloaded DLL mimicking VirtualBox
62.164.177[.]25IP AddressBackdoor.Turn C&C server
http://192.36.27[.]51/TechSupV18Fix3.zipURLMalicious ZIP archive download URL

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories