Sophia
Hart

DragonForce Uses Microsoft Teams Relays to Hide Backdoor.Turn Ransomware C2

Sophia Hart

Jun 22, 2026

5 min read

dragonforce ransomware

TL; DR

  • Researchers identified a custom backdoor called Backdoor.Turn in a DragonForce ransomware intrusion.
  • The malware used Microsoft Teams TURN relay infrastructure during C2 setup.
  • Attackers reportedly maintained access for one to two months.
  • Researchers observed DLL sideloading, BYOVD techniques, and security tool termination.
  • Backdoor.Turn was deployed after ransomware activity, potentially to maintain access.

DragonForce ransomware operators have been observed using Microsoft Teams relay infrastructure to conceal command-and-control (C2) communications associated with a custom backdoor called Backdoor.Turn.

Researchers from Symantec and Carbon Black identified the activity during an intrusion involving a major U.S. services company. The attackers reportedly remained in the victim environment for one to two months and used a combination of persistence and defense-evasion techniques, including DLL sideloading and Bring Your Own Vulnerable Driver (BYOVD) activity.

The incident highlights how threat actors can leverage trusted cloud infrastructure to reduce the visibility of malicious communications inside compromised environments.

Book a free demo and explore Hexnode today!

Researchers Uncover Backdoor.Turn in a DragonForce Ransomware Intrusion

Symantec and Carbon Black reported that DragonForce-linked actors deployed a custom Go-based remote access trojan named Backdoor.Turn during an intrusion targeting a major U.S. services organization.

Researchers observed the following activity during the investigation:

  • Deployment of Backdoor.Turn malware
  • DLL side-loading techniques
  • Creation of rogue user accounts
  • Firewall rule modifications
  • Driver-based security tool termination
  • Bring Your Own Vulnerable Driver (BYOVD) defense evasion
  • Backdoor deployment after ransomware activity

Researchers also observed Backdoor.Turn being injected into DbgView64.exe, a legitimate Sysinternals utility. The victim organization has not been publicly identified. Researchers reported that attackers maintained access to the environment for approximately one to two months.

How Microsoft Teams Infrastructure Was Used to Conceal C2 Traffic

One of the most notable aspects of the DragonForce ransomware intrusion was the way Backdoor.Turn established communications with attacker-controlled infrastructure.

According to researchers, the malware:

  • Obtains an anonymous Microsoft Teams visitor token from Microsoft’s Skype-backed identity services
  • Uses a legitimate Microsoft TURN relay during connection establishment
  • Establishes a QUIC session with the attacker-controlled command-and-control server

As a result, defenders monitoring network traffic may primarily observe outbound connections to legitimate Microsoft Teams infrastructure rather than attacker-controlled systems.

Researchers said this appears to be the first known real-world case of threat actors abusing Microsoft Teams TURN relay infrastructure for command-and-control communications.

The Attackers Didn’t Leave After Ransomware Deployment

Backdoor.Turn was reportedly deployed after ransomware activity had already taken place. Researchers observed the malware being injected into DbgView64.exe, a legitimate Sysinternals utility commonly used for debugging and diagnostic purposes.

Several findings suggest the intrusion continued beyond the ransomware stage:

  • Backdoor.Turn was deployed after ransomware execution
  • The malware was injected into DbgView64.exe
  • Attackers reportedly remained in the environment for one to two months
  • Researchers reported attacker access lasting approximately one to two months

The timing of the deployment suggests the attackers may have sought to maintain access after ransomware execution, although their long-term objectives were not publicly disclosed.

What Remains Unknown

Several details of the intrusion have not been publicly disclosed. Unknown factors include:

  • The initial access method used by the attackers
  • Whether vulnerabilities were exploited during the intrusion
  • The extent of data theft occurred
  • The full scope of affected systems
  • The attackers’ objectives for deploying Backdoor.Turn after ransomware execution

Security teams should treat the incident as an evolving threat event rather than a fully documented breach case.

Why Teams Relay Abuse Matters

The incident demonstrates how attackers can use trusted enterprise services to make malicious activity harder to detect.

Many organizations allow Microsoft Teams traffic as part of normal business operations. When malicious communications blend into legitimate cloud-service traffic, network-based indicators may become less effective.

Researchers also observed process injection, DLL side-loading, vulnerable driver abuse, and security tool tampering. These endpoint-level indicators can provide valuable context when malicious traffic appears legitimate.

While Microsoft Teams itself was not compromised, the abuse of Teams-related infrastructure shows how trusted services can become part of an attacker’s command-and-control workflow.

Investigation Priorities for Security Teams

Organizations reviewing similar activity should consider examining:

  • Teams-related connections originating from unexpected processes
  • DbgView64.exe execution in unusual contexts
  • DLL side-loading behavior
  • Unauthorized driver loading activity
  • Security tool termination attempts
  • Unexpected account creation activity
  • Unexpected firewall rule changes
  • Backdoor deployment following ransomware activity

Correlating endpoint, identity, and network telemetry can help uncover activity that may otherwise appear legitimate.

How Hexnode Supports Investigation and Response

The DragonForce investigation uncovered several Windows-based behaviors beyond the Teams relay abuse itself, including DLL side-loading and Backdoor.Turn injection into DbgView64.exe, vulnerable driver abuse, and security tool termination.

For security teams investigating similar activity, Hexnode XDR can help analyze endpoint telemetry, security events, and incident data across affected Windows devices to support threat investigation and response.

Hexnode UEM can help administrators enforce security policies, manage enrolled devices, and perform device actions across managed endpoints.

building a cybersecurity framework
Featured resource

Building a cybersecurity framework for your enterprise

Explore cybersecurity frameworks and how UEM strengthens security, visibility, compliance, and organizational resilience.

DOWNLOAD

Conclusion

The DragonForce ransomware incident shows how attackers continue to adapt command-and-control techniques to blend into legitimate enterprise activity. By leveraging Microsoft Teams relay infrastructure during communication setup, the attackers made malicious communications more difficult to distinguish from legitimate enterprise traffic.

When attackers abuse trusted cloud collaboration infrastructure, investigations often require endpoint telemetry alongside network visibility. Endpoint telemetry, behavioral analysis, and persistence hunting remain critical for identifying activity that may otherwise appear legitimate.

FAQs

Backdoor.Turn is a custom Go-based remote access trojan observed during a DragonForce-linked intrusion. Researchers reported that it used Microsoft Teams relay infrastructure during command-and-control setup.

Researchers did not report a compromise of Microsoft Teams. Instead, the attackers reportedly abused legitimate Teams-related relay infrastructure as part of their communication workflow.

The incident shows how attackers can use trusted cloud infrastructure to conceal malicious communications, making command-and-control activity more difficult to identify.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.