Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Microsoft Teams to Mask Ransomware Traffic

Hackers Exploit Microsoft Teams to Mask Ransomware Traffic

Posted on June 16, 2026 By CWS

Cybercriminals are increasingly manipulating trusted cloud platforms to avoid detection, with a recent campaign revealing how Microsoft Teams infrastructure is being exploited to conceal malicious activities.

The Symantec Threat Hunter Team has identified a new Go-based remote access Trojan (RAT) known as Backdoor.TURN. This malware utilizes Microsoft Teams TURN relay servers to mask command-and-control (C2) communications as legitimate enterprise traffic.

DragonForce Ransomware Campaign

This malicious activity is linked to DragonForce, a ransomware group targeting a major U.S. services company. The attackers managed to remain undetected for up to two months, according to Symantec’s findings.

The malware obscures its traffic by routing through Microsoft’s servers, making it appear as regular connections to Teams services. This tactic complicates detection efforts for security teams.

Technical Details of the Intrusion

Backdoor.TURN initiates its operations by obtaining an anonymous visitor token from Microsoft’s identity services. This token is used to authenticate with Teams infrastructure, establishing a relay session through TURN servers.

Once connected, a QUIC session is started with the actual C2 server. This method ensures that only benign traffic to Microsoft domains is visible, effectively hiding the malicious activity.

The initial attack vector is unclear, but Symantec suggests potential exploitation of SQL or MSSQL vulnerabilities or access through an initial access broker. The intrusion reportedly commenced in December 2025.

Advanced Evasion Techniques

The attackers employed a Bring Your Own Vulnerable Driver (BYOVD) technique to disable security tools at the kernel level. A Huawei driver, among others linked to specific CVEs, was exploited as a “Havoc Process Terminator.”

A custom driver, Abyss Worker, was also used, disguised as a legitimate Palo Alto driver, to terminate security processes. The Backdoor.TURN payload was injected into the DbgView64.exe process following ransomware execution.

Symantec’s analysis indicates that the malware could serve for persistence or enable future access, possibly for resale to other threat actors.

Symantec emphasizes that this is the first recorded instance of Microsoft Teams TURN relay infrastructure being used in this manner, highlighting a sophisticated evolution in hacking strategies.

Implications for Enterprise Security

DragonForce, tracked by Symantec as Hackledorb, has become a highly organized and advanced threat group. Their use of trusted cloud infrastructure coupled with novel exploitation techniques signifies a growing trend in cyberattacks.

Symantec warns that blending malicious traffic with legitimate services significantly reduces defenders’ visibility, stressing the need for enhanced behavioral detection and stricter control over vulnerable drivers and communication platforms.

For the latest updates on cybersecurity threats, follow us on Google News, LinkedIn, and X.

Cyber Security News Tags:Backdoor TURN, cloud infrastructure, cloud services, Cybersecurity, DragonForce, enterprise security, Hackers, Malware, Microsoft Teams, network security, Ransomware, remote access trojan, Symantec, threat detection, TURN servers

Post navigation

Previous Post: Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
Next Post: GitGuardian Enhances Developer Security with New Endpoint Protection

Related Posts

Top 10 Best Next‑Generation Firewall (NGFW) Providers in 2025 Top 10 Best Next‑Generation Firewall (NGFW) Providers in 2025 Cyber Security News
New NFCShare Malware Targets Android Banking Apps New NFCShare Malware Targets Android Banking Apps Cyber Security News
Critical Microsoft’s Entra ID Vulnerability Allows Attackers to Gain Complete Administrative Control Critical Microsoft’s Entra ID Vulnerability Allows Attackers to Gain Complete Administrative Control Cyber Security News
New Malware Via WhatsApp Exfiltrate Contacts to Attack Server and Deploys Malware New Malware Via WhatsApp Exfiltrate Contacts to Attack Server and Deploys Malware Cyber Security News
Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions Cyber Security News
Renault UK Suffers Cyberattack – Hackers Stolen Users Customers Personal Data Renault UK Suffers Cyberattack – Hackers Stolen Users Customers Personal Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitGuardian Enhances Developer Security with New Endpoint Protection
  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic
  • Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
  • Google Cloud Vertex AI SDK Flaw Exposed Model Uploads
  • Aembit Enhances IAM for Microsoft’s Copilot Studio

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitGuardian Enhances Developer Security with New Endpoint Protection
  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic
  • Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
  • Google Cloud Vertex AI SDK Flaw Exposed Model Uploads
  • Aembit Enhances IAM for Microsoft’s Copilot Studio

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark