Sophia
Hart

DragonForce Uses Microsoft Teams Relays to Hide Backdoor.Turn Ransomware C2

Sophia Hart

Jun 22, 2026

5 min read

dragonforce ransomware

TL; DR

  • Researchers identified a custom backdoor called Backdoor.Turn in a DragonForce ransomware intrusion.
  • The malware used Microsoft Teams TURN relay infrastructure during C2 setup.
  • Attackers reportedly maintained access for one to two months.
  • Researchers observed DLL sideloading, BYOVD techniques, and security tool termination.
  • Backdoor.Turn was deployed after ransomware activity, potentially to maintain access.

DragonForce ransomware operators have been observed using Microsoft Teams relay infrastructure to conceal command-and-control (C2) communications associated with a custom backdoor called Backdoor.Turn.

Researchers from Symantec and Carbon Black identified the activity during an intrusion involving a major U.S. services company. The attackers reportedly remained in the victim environment for one to two months and used a combination of persistence and defense-evasion techniques, including DLL sideloading and Bring Your Own Vulnerable Driver (BYOVD) activity.

The incident highlights how threat actors can leverage trusted cloud infrastructure to reduce the visibility of malicious communications inside compromised environments.

Book a free demo and explore Hexnode today!

Researchers Uncover Backdoor.Turn in a DragonForce Ransomware Intrusion

Symantec and Carbon Black reported that DragonForce-linked actors deployed a custom Go-based remote access trojan named Backdoor.Turn during an intrusion targeting a major U.S. services organization.

Researchers observed the following activity during the investigation:

  • Deployment of Backdoor.Turn malware
  • DLL side-loading techniques
  • Creation of rogue user accounts
  • Firewall rule modifications
  • Driver-based security tool termination
  • Bring Your Own Vulnerable Driver (BYOVD) defense evasion
  • Backdoor deployment after ransomware activity

Researchers also observed attackers injecting Backdoor.Turn into DbgView64.exe, a legitimate Sysinternals utility. The researchers have not publicly identified the victim organization. Researchers reported that attackers maintained access to the environment for approximately one to two months.

How Microsoft Teams Infrastructure Was Used to Conceal C2 Traffic

During the DragonForce ransomware intrusion, Backdoor.Turn notably established communications with infrastructure that attackers controlled.

According to researchers, the malware:

  • Obtains an anonymous Microsoft Teams visitor token from Microsoft’s Skype-backed identity services
  • Uses a legitimate Microsoft TURN relay during connection establishment
  • Establishes a QUIC session with the attacker-controlled command-and-control server

As a result, defenders monitoring network traffic may primarily observe outbound connections to legitimate Microsoft Teams infrastructure rather than attacker-controlled systems.

Researchers said this appears to be the first known real-world case of threat actors abusing Microsoft Teams TURN relay infrastructure for command-and-control communications.

The Attackers Didn’t Leave After Ransomware Deployment

Attackers reportedly deployed Backdoor.Turn after they had already carried out ransomware activity. Researchers observed the attackers injecting the malware into DbgView64.exe, a legitimate Sysinternals utility that administrators commonly use for debugging and diagnostic purposes.

Several findings suggest the intrusion continued beyond the ransomware stage:

  • Backdoor.Turn was deployed after ransomware execution
  • The malware was injected into DbgView64.exe
  • Attackers reportedly remained in the environment for one to two months
  • Researchers reported attacker access lasting approximately one to two months

The deployment’s timing suggests the attackers sought to maintain access after executing ransomware, although the report does not publicly disclose their long-term objectives.

What Remains Unknown

Several details of the intrusion have not been publicly disclosed. Unknown factors include:

  • The initial access method used by the attackers
  • Whether vulnerabilities were exploited during the intrusion
  • The extent of data theft occurred
  • The full scope of affected systems
  • The attackers’ objectives for deploying Backdoor.Turn after ransomware execution

Security teams should treat the incident as an evolving threat event rather than a fully documented breach case.

Why Teams Relay Abuse Matters

The incident demonstrates how attackers can use trusted enterprise services to make malicious activity harder to detect.

Many organizations allow Microsoft Teams traffic as part of normal business operations. When malicious communications blend into legitimate cloud-service traffic, network-based indicators may become less effective.

Researchers also observed process injection, DLL side-loading, vulnerable driver abuse, and security tool tampering. These endpoint-level indicators can provide valuable context when malicious traffic appears legitimate.

While attackers did not compromise Microsoft Teams itself, their abuse of Teams-related infrastructure highlights how they can exploit trusted services for a command-and-control workflow.

Investigation Priorities for Security Teams

Organizations reviewing similar activity should consider examining:

  • Teams-related connections originating from unexpected processes
  • DbgView64.exe execution in unusual contexts
  • DLL side-loading behavior
  • Unauthorized driver loading activity
  • Security tool termination attempts
  • Unexpected account creation activity
  • Unexpected firewall rule changes
  • Backdoor deployment following ransomware activity

Correlating endpoint, identity, and network telemetry can help uncover activity that may otherwise appear legitimate.

How Hexnode Supports Investigation and Response

The DragonForce investigation uncovered several Windows-based behaviors beyond the Teams relay abuse itself, including DLL side-loading and Backdoor.Turn injection into DbgView64.exe, vulnerable driver abuse, and security tool termination.

For security teams investigating similar activity, Hexnode XDR can help analyze endpoint telemetry, security events, and incident data across affected Windows devices to support threat investigation and response.

Hexnode UEM can help administrators enforce security policies, manage enrolled devices, and perform device actions across managed endpoints.

building a cybersecurity framework
Featured resource

Building a cybersecurity framework for your enterprise

Explore cybersecurity frameworks and how UEM strengthens security, visibility, compliance, and organizational resilience.

DOWNLOAD

Conclusion

The DragonForce ransomware incident shows how attackers continue to adapt command-and-control techniques to blend into legitimate enterprise activity. By leveraging Microsoft Teams relay infrastructure during communication setup, the attackers made malicious communications more difficult to distinguish from legitimate enterprise traffic.

When attackers abuse trusted cloud collaboration infrastructure, investigations often require endpoint telemetry alongside network visibility. Endpoint telemetry, behavioral analysis, and persistence hunting remain critical for identifying activity that may otherwise appear legitimate.

FAQs

Researchers observed Backdoor.Turn, a custom Go-based remote access trojan, during a DragonForce-linked intrusion. Researchers reported that it used Microsoft Teams relay infrastructure during command-and-control setup.

Researchers did not report a compromise of Microsoft Teams. Instead, the attackers reportedly abused legitimate Teams-related relay infrastructure as part of their communication workflow.

The incident shows how attackers can use trusted cloud infrastructure to conceal malicious communications, making command-and-control activity more difficult to identify.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.