Backdoor.Turn Microsoft Teams TURN relay malware activity
Malware Activity
Summary
Hide ▲
Show ▼
Backdoor.Turn is a Go-based RAT tied to DragonForce ransomware operators that hid command-and-control traffic through Microsoft Teams TURN relay infrastructure during a December 2025 intrusion. Symantec and Carbon Black said the malware obtained an anonymous Teams visitor token, used a legitimate Microsoft TURN relay, and then opened a QUIC session to the attacker’s real C2 server, making the traffic look like normal Microsoft activity. The activity was observed against a major U.S. services firm, and it paired relay-based stealth with DLL sideloading, BYOVD evasion, and DbgView64.exe process injection to maintain access.
Related Happenings
StealC and Amadey infostealer infrastructure disruption
Malware Activity
H score69
First: 24.06.2026 18:25
Last: 24.06.2026 18:25
Sources 1
About this happening:
StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...
StealC and Amadey infostealer infrastructure disruption
Malware ActivityAbout this happening: StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...
Mistic backdoor attack activity targeting enterprise sectors since April
Malware Activity
H score33
First: 24.06.2026 13:41
Last: 24.06.2026 13:41
Sources 1
About this happening:
The Mistic backdoor is being used in financially motivated attacks against insurance, education, IT, and professional services organizations, giving operators a stealt...
Mistic backdoor attack activity targeting enterprise sectors since April
Malware ActivityAbout this happening: The Mistic backdoor is being used in financially motivated attacks against insurance, education, IT, and professional services organizations, giving operators a stealt...
Major U.S. services company hit by ransomware attack linked to DragonForce
Incident
H score38
First: 16.06.2026 13:18
Last: 16.06.2026 13:18
Sources 1
How related:
The investigation report, published by Symantec and Carbon Black on 16 June, warned that attackers deployed DragonForce ransomware on the network of a “major US services firm.”
About this happening:
A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Major U.S. services company hit by ransomware attack linked to DragonForce
IncidentHow related: The investigation report, published by Symantec and Carbon Black on 16 June, warned that attackers deployed DragonForce ransomware on the network of a “major US services firm.”
About this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
KongTuke Microsoft Teams initial access campaign
Campaign
H score42
First: 14.05.2026 15:12
Last: 14.05.2026 15:12
Sources 1
About this happening:
The KongTuke campaign now uses Microsoft Teams social engineering to gain persistent access to corporate networks, shortening initial compromise to under five minute...
KongTuke Microsoft Teams initial access campaign
CampaignAbout this happening: The KongTuke campaign now uses Microsoft Teams social engineering to gain persistent access to corporate networks, shortening initial compromise to under five minute...
Major South Korean electronics manufacturer hit by data theft breach
Incident
H score13
First: 14.05.2026 00:59
Last: 14.05.2026 00:59
Sources 1
About this happening:
A major South Korean electronics manufacturer suffered a week-long intrusion in February 2026, giving attackers time to conduct reconnaissance, credential theft*...
Major South Korean electronics manufacturer hit by data theft breach
IncidentAbout this happening: A major South Korean electronics manufacturer suffered a week-long intrusion in February 2026, giving attackers time to conduct reconnaissance, credential theft*...
Timeline
-
16.06.2026 13:18 4 articles · 29d ago
Backdoor.Turn Microsoft Teams TURN relay malware activity
Initial DisclosureThe malware gained an early covert foothold by using Microsoft Teams TURN relay infrastructure for command-and-control setup. That opening stage let the operator mask remote communications before later reconnaissance, data theft, and ransomware deployment.
Show sources
- Ransomware gang abuses Microsoft Teams relays to hide malicious traffic — www.bleepingcomputer.com — 16.06.2026 13:18
- Ransomware gang abuses Microsoft Teams relays to hide malicious traffic — www.bleepingcomputer.com — 16.06.2026 13:18
- DragonForce Ransomware Exploited Microsoft Teams to Hide in Attack Against Major Company — www.infosecurity-magazine.com — 16.06.2026 14:30
- DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic — thehackernews.com — 18.06.2026 16:30