VMTech
Discuss a project

DragonForce masks C2 via Microsoft Teams TURN (Backdoor.Turn)

DragonForce masks C2 via Microsoft Teams TURN (Backdoor.Turn)

Colleagues, note: Backdoor.Turn is being used to conceal C2 traffic via Microsoft Teams TURN relays.

- Symantec/Carbon Black: Go‑RAT obtains an anonymous Teams token and establishes a QUIC session to C2 via legitimate TURN.
- Initial access: vulnerable SQL/MS‑SQL or purchase; then DLL sideloading and BYOVD driver.
- Capabilities: command execution, network scanning, AD/LDAP discovery, credential theft and lateral movement.

Why it matters: attackers hide traffic within legitimate cloud services, complicating detection.

How are you strengthening monitoring of outbound connections to cloud services?

#cybersecurity #ransomware #ThreatIntel

Open analytics
On the site 0 views
min read 1 18.06.2026
On Instagram 4 views
On Instagram 1 reach
Instagram

DragonForce masks C2 via Microsoft Teams TURN (Backdoor.Turn)

Open the post on Instagram ↗