DragonForce masks C2 via Microsoft Teams TURN (Backdoor.Turn)

Colleagues, note: Backdoor.Turn is being used to conceal C2 traffic via Microsoft Teams TURN relays.
- Symantec/Carbon Black: Go‑RAT obtains an anonymous Teams token and establishes a QUIC session to C2 via legitimate TURN.
- Initial access: vulnerable SQL/MS‑SQL or purchase; then DLL sideloading and BYOVD driver.
- Capabilities: command execution, network scanning, AD/LDAP discovery, credential theft and lateral movement.
Why it matters: attackers hide traffic within legitimate cloud services, complicating detection.
How are you strengthening monitoring of outbound connections to cloud services?
#cybersecurity #ransomware #ThreatIntel

