Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack

    June 17, 2026

    Low Water at San Carlos Reservoir

    June 17, 2026

    Android 17 stable update is rolling out to Pixel phones

    June 17, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
    Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
    Cybersecurity

    Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack

    The Tech GuyBy The Tech GuyJune 17, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    A new backdoor deployed as part of a recent DragonForce ransomware attack is using Microsoft Teams relay servers for command-and-control (C&C), according to Broadcom’s Symantec and Carbon Black threat hunter team.

    Advertisement

    The DragonForce group has been active since 2023, operating as a cartel structure and adopting highly advanced techniques in recent months, suggesting organizational maturity and significant resource allocation.

    Tracked as Backdoor.Turn, the newly identified malware is written in Go and hides its C&C server communication as legitimate Microsoft Teams traffic in a sophisticated manner.

    “Backdoor.Turn obtains an anonymous Teams visitor token from Microsoft’s Skype-backed identity services, uses a legitimate Microsoft TURN relay to set up the connection, and then runs a QUIC session to the attacker’s real [C&C] server,” the threat hunters note.

    According to the researchers, this appears to be the first malware family to abuse the TURN relay infrastructure in this way.

    “It is relatively unusual to see ransomware attackers using their own custom tools, and it is particularly unusual to see them using a custom tool as sophisticated as Backdoor.Turn,” they note.

    Advertisement. Scroll to continue reading.

    The custom backdoor was used in an attack on a US services firm, which was likely compromised through an unknown vulnerability in an SQL or MSSQL server. DragonForce operators might have purchased access to the company from an access broker.

    According to Symantec and Carbon Black, the hackers accessed the victim network in December 2025, and relied on DLL sideloading to execute code that would fetch additional malware from remote servers.

    The hackers established persistence, secured access to the compromised environment, conducted reconnaissance, and employed a sophisticated BYOVD strategy to exploit known flaws in signed drivers, thereby obtaining kernel-level access and terminating security processes.

    They also deployed the DragonForce ransomware for data encryption and exfiltration, and the Backdoor.Turn malware to maintain persistence on the compromised systems after the ransomware is deployed.

    The backdoor enables threat actors to execute commands, create processes, perform network scanning and LDAP/AD mapping, move laterally using stolen credentials, and exfiltrate credentials from the browsers installed on the infected systems.

    “The attackers in this campaign use exceptionally sophisticated cyber tradecraft. The configuration of Backdoor.Turn means that security products only see C&C traffic going to legitimate Teams servers, leaving defenders unaware that data is being siphoned away by malicious actors,” the researchers note.

    Related: Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer

    Related: Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges

    Related: FBI: Cybercrime Losses Neared $21 Billion in 2025

    Related: Threat Actor Connected to Play, RansomHub and DragonForce Ransomware Operations

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Magnitude Emerges From Stealth Mode With $10 Million in Funding

    June 17, 2026

    Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker

    June 16, 2026

    iRhythm Confirms Data Stolen in Hack

    June 16, 2026

    Cybersecurity Executives Urge the Trump Administration to Ease Restrictions on Anthropic AI Models

    June 16, 2026

    NewCore Emerges From Stealth Mode With $66 Million in Funding

    June 16, 2026

    Chinese Hackers Target Medical, Military, and AI Research in North America

    June 15, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 202672 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 202618 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack

    June 17, 2026

    Low Water at San Carlos Reservoir

    June 17, 2026

    Android 17 stable update is rolling out to Pixel phones

    June 17, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.