Threat actors associated with the DragonForce have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to hide command and control (C2) traffic within the Microsoft Teams relay infrastructure.
See also: Abuse of Microsoft Teams and Quick Assist to distribute A0Backdoor

According to findings from Symantec, which is owned by Broadcom and Carbon Black, the backdoor was deployed against a large American services company, although the company's name was not disclosed.
“Backdoor.Turn obtains an anonymous Teams guest token from Microsoft’s Skype-backed identity services, uses a legitimate Microsoft TURN relay to establish the connection, and then executes a QUIC session to the attacker’s real command and control (C2) server,” the Threat Hunters Group said in a report shared with The Hacker News.
“For network defenders, the only traffic they could see was outbound connections to legitimate Microsoft Teams servers. The attackers had been on the victim's network for between one and two months.“
This is the first publicly documented case of threat actors exploiting Microsoft's TURN (Traversal Using Relays around NAT) relay infrastructure.
It is suspected that the threat actor gained initial access by exploiting a vulnerability in either a SQL or MS-SQL server, although the exact nature of the flaw is unknown. It is also possible that access was gained through an initial access broker (IAB).
The initial malicious activity on the victim’s network began in December 2025, with the attackers executing a PowerShell command to drop a ZIP file under the guise of a technical support patch. The ZIP file was responsible for launching a DLL side-loading attack, which then executed a malicious DLL to conduct reconnaissance, create persistence, and silence security software using a Huawei driver (“HWAuidoOs2Ec.sys”).
See also: Microsoft is removing Teams' Together Mode

This was achieved through a technical attack called BYOVD. The driver has been used in a large-scale malicious advertising campaign targeting people in the US looking for tax-related documents, although this is said to have happened after the ransomware incident.
Some of the other drivers used for this purpose include:
- wsftprm.sys (CVE-2023-52271)
- GameDriverX64.sys (CVE-2025-61155)
- K7RKScan.sys (CVE-2025-1055)
- ABYSSWORKER, a malicious driver previously observed in Medusa ransomware attacks
Significantly, the execution of Backdoor.Turn involved injecting itself into the legitimate process “DbgView64.exe” after the DragonForce ransomware was deployed. This suggests an attempt to maintain continuous access to the compromised computer for future attacks or resale for profit.
The underlying mechanism of the TURN- based Backdoor.Turn relies on an invisible C2 communication technique called Ghost Calls , which was documented by Praetorian in August 2024. The backdoor supports a wide range of capabilities, including command execution, process creation, network scanning, LDAP and Active Directory lookup, credential-based lateral movement, and browser credential theft.
See also: M&S: Confirms it was targeted by DragonForce ransomware

The findings depict a group of hackers using sophisticated cyberattack techniques to execute targeted, high-impact attacks, leaving victims unsuspecting as they secretly extract data. This is particularly significant as Hackledorb, the threat actor behind DragonForce, has moved from a conventional ransomware-as-a-service (RaaS) model to a highly organized, standardized cartel structure.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
