DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
DragonForce hackers used a custom Go-based remote access trojan to conceal command-and-control traffic inside Microsoft Teams relay infrastructure. The backdoor was deployed against a major U.S. services firm.
Intelligence analysis by Llama 3.3 70B

The DragonForce ransomware group has been observed using a custom backdoor to hide C2 traffic within Microsoft Teams relays, marking a new level of sophistication in their attacks.
Imagine you're playing a game of hide-and-seek with a friend. Your friend is hiding in a place that looks like a normal part of the game, so you can't find them. That's kind of what the DragonForce hackers are doing with their malware - they're hiding it inside a legitimate service like Microsoft Teams, making it hard for defenders to find.
Analysis
The Evolution of DragonForce Tactics
The DragonForce ransomware group has been actively developing and deploying new techniques to evade detection and maintain access to compromised hosts. The use of a custom Go-based remote access trojan, Backdoor.Turn, is a significant example of this evolution. By leveraging the Microsoft Teams relay infrastructure, the attackers can conceal their command-and-control traffic, making it difficult for defenders to identify and block the malicious activity.
The backdoor's ability to obtain an anonymous Teams visitor token and use a legitimate Microsoft TURN relay to set up the connection allows the attackers to blend in with legitimate traffic. This tactic, combined with the use of a QUIC session to the attacker's real C2 server, makes it challenging for network defenders to detect the malicious activity.
The Significance of BYOVD Technique
The DragonForce group's use of the bring your own vulnerable driver (BYOVD) technique is another notable aspect of their attack. By exploiting vulnerabilities in drivers, the attackers can gain elevated privileges and maintain access to the compromised host. The use of a Huawei driver, in particular, highlights the importance of keeping software up to date and patching vulnerabilities in a timely manner.
The Implications of Sophisticated Cyber Tradecraft
The DragonForce group's sophisticated cyber tradecraft, including the use of Ghost Calls and TURN-based mechanisms, paints a picture of a highly organized and formalized cartel structure. The group's ability to develop and deploy new techniques, such as the Backdoor.Turn, demonstrates their commitment to staying ahead of defenders. This level of sophistication makes it essential for organizations to invest in advanced threat detection and prevention capabilities to stay ahead of these threats.
The operational timeline of the DragonForce group reveals a pattern of continuous capability development, with the adoption of highly advanced techniques becoming a hallmark of their post-2025 activity. The deployment of Backdoor.Turn, combined with their multi-vector BYOVD evasion, marks them as one of the most capable and persistent ransomware groups operating today.
Key points
- DragonForce hackers used a custom Go-based remote access trojan to conceal C2 traffic within Microsoft Teams relay infrastructure
- The backdoor was deployed against a major U.S. services firm
- The attackers used a legitimate Microsoft TURN relay to set up the connection and a QUIC session to the attacker's real C2 server
The discovery of this new tactic by the DragonForce group can help organizations improve their defenses against similar attacks. By understanding how the attackers are using legitimate services to conceal their activity, defenders can develop new strategies to detect and prevent these threats. Additionally, the development of advanced threat detection and prevention capabilities can help stay ahead of these sophisticated threats.
The use of legitimate services like Microsoft Teams to conceal malicious activity makes it challenging for defenders to identify and block these threats. The sophistication of the DragonForce group's tactics, including the use of BYOVD and Ghost Calls, highlights the need for organizations to be vigilant in detecting and preventing these attacks. If left unchecked, these threats can lead to significant financial and reputational damage.



