<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic-w9qf9jps7" -->

---
title: Ransomware gang abuses Microsoft Teams relays to hide...
description: DragonForce ransomware deployed a custom Go-based backdoor called &#x27;Backdoor.Turn&#x27; that abuses Microsoft Teams&#x27; TURN relay infrastructure to disguise...
canonical: https://daily.dev/posts/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic-w9qf9jps7
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Ransomware gang abuses Microsoft Teams relays to hide malicious traffic | daily.dev
og:description: DragonForce ransomware deployed a custom Go-based backdoor called &#x27;Backdoor.Turn&#x27; that abuses Microsoft Teams&#x27; TURN relay infrastructure to disguise...
og:url: https://daily.dev/posts/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic-w9qf9jps7
og:image: https://api.daily.dev/og/posts/W9qF9jpS7.png
og:image:alt: Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Ransomware gang abuses Microsoft Teams relays to hide malicious traffic

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

DragonForce ransomware deployed a custom Go-based backdoor called 'Backdoor.Turn' that abuses Microsoft Teams' TURN relay infrastructure to disguise command-and-control traffic as legitimate Teams network activity. The malware obtains an anonymous Teams visitor token and routes C2 communications through Microsoft's own relay servers, making detection difficult. The attack, observed in December 2025 against a major U.S. services company, also leveraged multiple BYOVD techniques using vulnerable drivers (including CVEs in Topaz Antifraud, Tower of Fantasy, and K7 Security drivers) to gain kernel-level privileges and disable security tools. Backdoor.Turn is the first known in-the-wild malware to exploit Teams TURN relays for C2. Capabilities include command execution, network scanning, LDAP/AD searching, and browser credential theft. Symantec published IoCs to help defenders identify and block these attacks.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic>

## Similar posts on daily.dev

- [Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor](https://daily.dev/posts/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor-o72rlfxfb) · Security Boulevard · 0 upvotes · 0 comments
- [Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic](https://daily.dev/posts/crooks-found-a-new-way-to-collaborate-using-teams-by-hiding-command-and-control-traffic-c4zhsotyu) · The Register · 0 upvotes · 0 comments

---

Tags: [#ransomware](https://daily.dev/tags/ransomware)

[View this post on daily.dev](https://daily.dev/posts/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic-w9qf9jps7)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Ransomware gang abuses Microsoft Teams relays to hide malicious traffic","url":"https://daily.dev/posts/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic-w9qf9jps7","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic-w9qf9jps7"},"datePublished":"2026-06-16T10:22:22.415Z","dateModified":"2026-06-16T10:23:35.775Z","description":"DragonForce ransomware deployed a custom Go-based backdoor called 'Backdoor.Turn' that abuses Microsoft Teams' TURN relay infrastructure to disguise...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/756d9c6e1f32fe077e88c530f6c5c237?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/756d9c6e1f32fe077e88c530f6c5c237?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic-w9qf9jps7","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ransomware","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Ransomware gang abuses Microsoft Teams relays to hide malicious traffic"}]}
```

