DragonForce Backdoor.Turn — Microsoft Teams TURN Relay C2: Attack Chain & Detection

How DragonForce ransomware operators abused Microsoft Teams TURN server relays to bypass firewall egress filtering for C2 traffic.

DragonForce Backdoor.Turn — Microsoft Teams TURN Relay C2: Attack Chain & Detection
📌
Security Roundup Series: Week of June 18, 2026 • 4 min read deep dive

This post is part of the Week of June 19, 2026 Security Roundup.

Overview

Security researchers at Broadcom's Symantec and Carbon Black teams have identified a novel backdoor — Backdoor.Turn — deployed as part of a DragonForce ransomware intrusion at a US services firm. The malware is the first known threat to abuse the Traversal Using Relays around NAT (TURN) protocol used by Microsoft Teams, hiding its command-and-control (C2) communications inside Microsoft's own relay infrastructure.

What Is TURN and Why Does This Matter?

TURN (RFC 5766) is a protocol used by real-time communications applications — including Microsoft Teams — to relay media and data when direct peer-to-peer connections cannot be established. Teams clients obtain anonymous TURN relay sessions from Microsoft's Skype-backed identity services to ensure connectivity through corporate firewalls and NAT. Since these TURN relays are hosted by Microsoft and the traffic looks like legitimate Teams communications, most enterprise security tools treat it as trusted.

Backdoor.Turn exploits this trust relationship. It:

  1. Obtains an anonymous Teams visitor token from Microsoft's identity endpoint — no Teams account required.
  2. Uses a legitimate Microsoft TURN relay to establish a relay session.
  3. Tunnels a QUIC session over the TURN relay to the attacker's actual C2 server.

The result is C2 traffic that originates from *.teams.microsoft.com relay infrastructure — indistinguishable from normal Teams traffic to most network monitoring tools.

Technical Capabilities

Once installed, Backdoor.Turn enables the attacker to:

  • Execute arbitrary commands and create processes
  • Perform network scanning and LDAP/Active Directory enumeration
  • Move laterally using harvested credentials
  • Exfiltrate credentials from Chrome, Firefox, and Edge browser stores
  • Download and execute additional payloads

Attack Chain

The full DragonForce intrusion chain at the affected US firm:

  1. Initial access (December 2025): Exploitation of an unspecified vulnerability in an internet-facing SQL/MSSQL server.
  2. Persistence: DLL sideloading to execute code fetching additional malware from remote servers.
  3. Defense evasion (BYOVD): Multi-vector Bring Your Own Vulnerable Driver strategy — exploited signed but vulnerable drivers from Huawei, Topaz Antifraud, Tower of Fantasy, and K7 Security to gain kernel-level privileges and disable security tools (EDR/AV).
  4. C2 establishment: Backdoor.Turn deployed; C2 communications hidden inside Microsoft Teams TURN relay traffic.
  5. Lateral movement: AD enumeration, credential harvesting, internal network scanning.
  6. Dwell time: Attackers remained undetected for approximately two months (December 2025 – February 2026).
  7. Ransomware deployment: DragonForce ransomware detonated.

IOCs

  • C2 protocol: QUIC session tunneled over Microsoft TURN relay (traffic appears to originate from Teams relay endpoints)
  • Dropped drivers (BYOVD): Check for unusual loading of Huawei, Topaz Antifraud, Tower of Fantasy, K7 Security drivers outside their normal application contexts
  • Anomaly indicator: Teams TURN relay sessions originating from non-Teams processes (e.g., services, DLL-injected processes)

Detection Recommendations

  • Monitor for QUIC traffic (UDP 443) from non-Teams processes to Microsoft relay IP ranges
  • Alert on DLL sideloading patterns — especially from non-standard directories
  • Audit loaded kernel drivers for known vulnerable BYOVD targets (Huawei NDISProxy, Topaz Antifraud, etc.)
  • Enable Microsoft Defender Credential Guard to protect credential material from harvesting
  • Segment SQL/database servers from internet-facing exposure; require MFA for all remote management access

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther