Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Microsoft Teams to Mask Ransomware Traffic

Hackers Exploit Microsoft Teams to Mask Ransomware Traffic

Posted on June 16, 2026 By CWS

Cybercriminals are increasingly manipulating trusted cloud platforms to avoid detection, with a recent campaign revealing how Microsoft Teams infrastructure is being exploited to conceal malicious activities.

The Symantec Threat Hunter Team has identified a new Go-based remote access Trojan (RAT) known as Backdoor.TURN. This malware utilizes Microsoft Teams TURN relay servers to mask command-and-control (C2) communications as legitimate enterprise traffic.

DragonForce Ransomware Campaign

This malicious activity is linked to DragonForce, a ransomware group targeting a major U.S. services company. The attackers managed to remain undetected for up to two months, according to Symantec’s findings.

The malware obscures its traffic by routing through Microsoft’s servers, making it appear as regular connections to Teams services. This tactic complicates detection efforts for security teams.

Technical Details of the Intrusion

Backdoor.TURN initiates its operations by obtaining an anonymous visitor token from Microsoft’s identity services. This token is used to authenticate with Teams infrastructure, establishing a relay session through TURN servers.

Once connected, a QUIC session is started with the actual C2 server. This method ensures that only benign traffic to Microsoft domains is visible, effectively hiding the malicious activity.

The initial attack vector is unclear, but Symantec suggests potential exploitation of SQL or MSSQL vulnerabilities or access through an initial access broker. The intrusion reportedly commenced in December 2025.

Advanced Evasion Techniques

The attackers employed a Bring Your Own Vulnerable Driver (BYOVD) technique to disable security tools at the kernel level. A Huawei driver, among others linked to specific CVEs, was exploited as a “Havoc Process Terminator.”

A custom driver, Abyss Worker, was also used, disguised as a legitimate Palo Alto driver, to terminate security processes. The Backdoor.TURN payload was injected into the DbgView64.exe process following ransomware execution.

Symantec’s analysis indicates that the malware could serve for persistence or enable future access, possibly for resale to other threat actors.

Symantec emphasizes that this is the first recorded instance of Microsoft Teams TURN relay infrastructure being used in this manner, highlighting a sophisticated evolution in hacking strategies.

Implications for Enterprise Security

DragonForce, tracked by Symantec as Hackledorb, has become a highly organized and advanced threat group. Their use of trusted cloud infrastructure coupled with novel exploitation techniques signifies a growing trend in cyberattacks.

Symantec warns that blending malicious traffic with legitimate services significantly reduces defenders’ visibility, stressing the need for enhanced behavioral detection and stricter control over vulnerable drivers and communication platforms.

For the latest updates on cybersecurity threats, follow us on Google News, LinkedIn, and X.

Cyber Security News Tags:Backdoor TURN, cloud infrastructure, cloud services, Cybersecurity, DragonForce, enterprise security, Hackers, Malware, Microsoft Teams, network security, Ransomware, remote access trojan, Symantec, threat detection, TURN servers

Post navigation

Previous Post: Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
Next Post: GitGuardian Enhances Developer Security with New Endpoint Protection

Related Posts

71,000+ WatchGuard Devices Vulnerable to Remote Code Execution Attacks 71,000+ WatchGuard Devices Vulnerable to Remote Code Execution Attacks Cyber Security News
CISA Releases Best Security Practices Guide for Hardening Microsoft Exchange Server CISA Releases Best Security Practices Guide for Hardening Microsoft Exchange Server Cyber Security News
First-ever AI-powered ‘MalTerminal’ Malware uses OpenAI GPT-4 to Generate Ransomware Code First-ever AI-powered ‘MalTerminal’ Malware uses OpenAI GPT-4 to Generate Ransomware Code Cyber Security News
Global Threat: BADIIS Malware Compromises 1,800 Servers Global Threat: BADIIS Malware Compromises 1,800 Servers Cyber Security News
Interpol Taken Down 6 Ransomware Variants and Arrested 500+ Suspects Interpol Taken Down 6 Ransomware Variants and Arrested 500+ Suspects Cyber Security News
New EDR-Redir Tool Breaks EDR Exploiting Bind Filter and Cloud Filter Driver New EDR-Redir Tool Breaks EDR Exploiting Bind Filter and Cloud Filter Driver Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows 11 Enhances Taskbar and AI Features
  • Top Cloud Firewall Solutions for 2026: A Comprehensive Guide
  • Balance Theory Secures $19M for Cybersecurity Investment Platform
  • Critical Ruby on Rails Vulnerability Patched
  • Hackers Exploit Adform Script to Alter Crypto Wallets

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows 11 Enhances Taskbar and AI Features
  • Top Cloud Firewall Solutions for 2026: A Comprehensive Guide
  • Balance Theory Secures $19M for Cybersecurity Investment Platform
  • Critical Ruby on Rails Vulnerability Patched
  • Hackers Exploit Adform Script to Alter Crypto Wallets

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark