Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Microsoft Teams to Mask Ransomware Traffic

Hackers Exploit Microsoft Teams to Mask Ransomware Traffic

Posted on June 16, 2026 By CWS

Cybercriminals are increasingly manipulating trusted cloud platforms to avoid detection, with a recent campaign revealing how Microsoft Teams infrastructure is being exploited to conceal malicious activities.

The Symantec Threat Hunter Team has identified a new Go-based remote access Trojan (RAT) known as Backdoor.TURN. This malware utilizes Microsoft Teams TURN relay servers to mask command-and-control (C2) communications as legitimate enterprise traffic.

DragonForce Ransomware Campaign

This malicious activity is linked to DragonForce, a ransomware group targeting a major U.S. services company. The attackers managed to remain undetected for up to two months, according to Symantec’s findings.

The malware obscures its traffic by routing through Microsoft’s servers, making it appear as regular connections to Teams services. This tactic complicates detection efforts for security teams.

Technical Details of the Intrusion

Backdoor.TURN initiates its operations by obtaining an anonymous visitor token from Microsoft’s identity services. This token is used to authenticate with Teams infrastructure, establishing a relay session through TURN servers.

Once connected, a QUIC session is started with the actual C2 server. This method ensures that only benign traffic to Microsoft domains is visible, effectively hiding the malicious activity.

The initial attack vector is unclear, but Symantec suggests potential exploitation of SQL or MSSQL vulnerabilities or access through an initial access broker. The intrusion reportedly commenced in December 2025.

Advanced Evasion Techniques

The attackers employed a Bring Your Own Vulnerable Driver (BYOVD) technique to disable security tools at the kernel level. A Huawei driver, among others linked to specific CVEs, was exploited as a “Havoc Process Terminator.”

A custom driver, Abyss Worker, was also used, disguised as a legitimate Palo Alto driver, to terminate security processes. The Backdoor.TURN payload was injected into the DbgView64.exe process following ransomware execution.

Symantec’s analysis indicates that the malware could serve for persistence or enable future access, possibly for resale to other threat actors.

Symantec emphasizes that this is the first recorded instance of Microsoft Teams TURN relay infrastructure being used in this manner, highlighting a sophisticated evolution in hacking strategies.

Implications for Enterprise Security

DragonForce, tracked by Symantec as Hackledorb, has become a highly organized and advanced threat group. Their use of trusted cloud infrastructure coupled with novel exploitation techniques signifies a growing trend in cyberattacks.

Symantec warns that blending malicious traffic with legitimate services significantly reduces defenders’ visibility, stressing the need for enhanced behavioral detection and stricter control over vulnerable drivers and communication platforms.

For the latest updates on cybersecurity threats, follow us on Google News, LinkedIn, and X.

Cyber Security News Tags:Backdoor TURN, cloud infrastructure, cloud services, Cybersecurity, DragonForce, enterprise security, Hackers, Malware, Microsoft Teams, network security, Ransomware, remote access trojan, Symantec, threat detection, TURN servers

Post navigation

Previous Post: Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
Next Post: GitGuardian Enhances Developer Security with New Endpoint Protection

Related Posts

Perplexity’s Comet Browser Screenshot Feature Vulnerability Let Attackers Inject Malicious Prompts Perplexity’s Comet Browser Screenshot Feature Vulnerability Let Attackers Inject Malicious Prompts Cyber Security News
Threat Actors Impersonate Fake Docusign Notifications To Steal Corporate Data Threat Actors Impersonate Fake Docusign Notifications To Steal Corporate Data Cyber Security News
ESPHome Web Server Authentication Bypass Vulnerability Exposes Smart Devices ESPHome Web Server Authentication Bypass Vulnerability Exposes Smart Devices Cyber Security News
Massive “Shai-Halud” Supply Chain Attack Compromised 477 NPM Packages Massive “Shai-Halud” Supply Chain Attack Compromised 477 NPM Packages Cyber Security News
Critical Vivotek Vulnerability Allows Remote Users to Inject Arbitrary Code Critical Vivotek Vulnerability Allows Remote Users to Inject Arbitrary Code Cyber Security News
China-Nexus Hackers Exploiting VMware vCenter Environments to Deploy Web Shells and Malware Implants China-Nexus Hackers Exploiting VMware vCenter Environments to Deploy Web Shells and Malware Implants Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit GitHub Actions to Insert Miasma Malware
  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit GitHub Actions to Insert Miasma Malware
  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark