Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
A ransomware gang is using Microsoft Teams relays to hide malicious traffic. The gang, known as DragonForce, uses a custom malware called Backdoor.Turn to abuse the Traversal Using Relays around NAT (TURN) protocol.
Intelligence analysis by Llama 3.3 70B

DragonForce ransomware gang is using a custom malware to hide command-and-control traffic inside Microsoft Teams relay infrastructure, making it difficult for defenders to detect.
Imagine you're playing a game with your friends, and you want to send each other secret messages. But instead of using a special messenger, you use a public chat room to send your messages, so it looks like you're just talking to each other normally. That's kind of what this ransomware gang is doing, but instead of sending secret messages, they're sending bad code to take over computers.
Analysis
The DragonForce ransomware gang has been found to be using a custom malware called Backdoor.Turn to abuse the Traversal Using Relays around NAT (TURN) protocol used by Microsoft Teams. This protocol is used to distribute messages when a direct connection to the client is unavailable, such as when clients are on a private network. The Backdoor.Turn malware obtains an anonymous Teams visitor token and uses a legitimate Microsoft TURN relay server during connection setup to establish communication with the command-and-control (C2) server. This allows the malware to hide its communications within a trusted network, making it difficult for defenders to detect. The DragonForce gang has been linked to the infamous Scattered Spider threat group and has been active since at least 2023. The gang has adopted a cartel-style organizational structure and has been known to use sophisticated cyber tradecraft. In an attack observed in December 2025, the gang used the Backdoor.Turn malware to gain access to a major U.S. services company. The attack began with the exploitation of an unknown flaw in an SQL or MSSQL server, and the attackers then downloaded a ZIP archive containing a legitimate VirtualBox/DbgView executable and a malicious DLL file used for sideloading. The attackers then used Bring Your Own Vulnerable Driver (BYOVD) tactics to obtain kernel-level privileges and terminate security tools on the host. The Backdoor.Turn malware was injected into the 'DbgView64.exe' process after the ransomware was deployed, suggesting that it may be intended for persistence or future access. The malware has a range of capabilities, including command execution, process creation, network scanning, TLS certificate capturing, LDAP/Active Directory searching, website title collection, and browser credential theft. The use of Microsoft Teams relays to hide malicious traffic is a new tactic that has not been seen before, and it highlights the need for defenders to be vigilant and to monitor their networks for suspicious activity.
Key points
- DragonForce ransomware gang is using Microsoft Teams relays to hide malicious traffic
- The gang uses a custom malware called Backdoor.Turn to abuse the Traversal Using Relays around NAT (TURN) protocol
- The malware obtains an anonymous Teams visitor token and uses a legitimate Microsoft TURN relay server during connection setup
The discovery of this new tactic by the DragonForce gang may lead to improved defenses against ransomware attacks. By understanding how the gang is using Microsoft Teams relays to hide malicious traffic, defenders can develop new strategies to detect and prevent such attacks. Additionally, the publication of indicators of compromise (IoCs) by Symantec may help defenders to catch and block similar attacks in the future.
The use of Microsoft Teams relays to hide malicious traffic is a concerning development, as it shows how ransomware gangs are becoming increasingly sophisticated in their tactics. This may lead to more successful ransomware attacks, as defenders may struggle to detect the malicious activity. Additionally, the fact that the DragonForce gang was able to exploit an unknown flaw in an SQL or MSSQL server highlights the need for organizations to prioritize patching and vulnerability management.



