Find notable cyber news and cases, enriched with sources, timelines, and signals.

Backdoor.Turn Microsoft Teams TURN relay malware activity

Malware Activity
First reported
Last updated
Happening score
H score 29
3 unique sources, 3 articles

Summary

Hide ▲

Backdoor.Turn is a Go-based RAT tied to DragonForce ransomware operators that hid command-and-control traffic through Microsoft Teams TURN relay infrastructure during a December 2025 intrusion. Symantec and Carbon Black said the malware obtained an anonymous Teams visitor token, used a legitimate Microsoft TURN relay, and then opened a QUIC session to the attacker’s real C2 server, making the traffic look like normal Microsoft activity. The activity was observed against a major U.S. services firm, and it paired relay-based stealth with DLL sideloading, BYOVD evasion, and DbgView64.exe process injection to maintain access.

Related Happenings

StealC and Amadey infostealer infrastructure disruption

Malware Activity
H score69 First: 24.06.2026 18:25 Last: 24.06.2026 18:25 Sources 1

About this happening: StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...

Mistic backdoor attack activity targeting enterprise sectors since April

Malware Activity
H score33 First: 24.06.2026 13:41 Last: 24.06.2026 13:41 Sources 1

About this happening: The Mistic backdoor is being used in financially motivated attacks against insurance, education, IT, and professional services organizations, giving operators a stealt...

Major U.S. services company hit by ransomware attack linked to DragonForce

Incident
H score38 First: 16.06.2026 13:18 Last: 16.06.2026 13:18 Sources 1

How related: The investigation report, published by Symantec and Carbon Black on 16 June, warned that attackers deployed DragonForce ransomware on the network of a “major US services firm.”

About this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...

KongTuke Microsoft Teams initial access campaign

Campaign
H score42 First: 14.05.2026 15:12 Last: 14.05.2026 15:12 Sources 1

About this happening: The KongTuke campaign now uses Microsoft Teams social engineering to gain persistent access to corporate networks, shortening initial compromise to under five minute...

Major South Korean electronics manufacturer hit by data theft breach

Incident
H score13 First: 14.05.2026 00:59 Last: 14.05.2026 00:59 Sources 1

About this happening: A major South Korean electronics manufacturer suffered a week-long intrusion in February 2026, giving attackers time to conduct reconnaissance, credential theft*...

Timeline

  1. 16.06.2026 13:18 4 articles · 29d ago

    Backdoor.Turn Microsoft Teams TURN relay malware activity

    Initial Disclosure

    The malware gained an early covert foothold by using Microsoft Teams TURN relay infrastructure for command-and-control setup. That opening stage let the operator mask remote communications before later reconnaissance, data theft, and ransomware deployment.

    Show sources