DragonForce Ransomware Abuses Microsoft Teams TURN Relays to Hide Backdoor.Turn C2 Traffic — Threadlinqs Intelligence
As of 2026-06-16, DragonForce Ransomware Abuses Microsoft Teams TURN Relays to Hide Backdoor.Turn C2 Traffic is a critical-severity ransomware threat attributed to DragonForce (MY), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-2181 · Severity: CRITICAL · Status: ACTIVE · Category: RANSOMWARE
Attribution: DragonForce · MY · FINANCIAL
Symantec's Broadcom Threat Hunter Team identified Backdoor.Turn, a Go-based backdoor deployed by the DragonForce ransomware cartel (tracked as Hackledorb), that abuses legitimate Microsoft Teams TURN
Symantec/Broadcom's Threat Hunter Team documented an intrusion at a U.S. services firm in which the DragonForce ransomware cartel (the group Symantec tracks internally as Hackledorb) maintained access for one to two months before deploying its ransomware payload. Initial access is suspected to involve exploitation of an internet-facing SQL or Microsoft SQL Server, or purchase of existing access from an initial access broker; the exact entry point was not conclusively determined. In December 2025 the operators executed PowerShell commands to retrieve a ZIP archive disguised as a tech-support hotfix ('TechSupV18Fix3.zip') from 192.36.27.51, then used DLL side-loading of a legitimate VirtualBox/DbgView64.exe binary paired with a malicious 'vboxrt.dll' to run reconnaissance and evasion code.
The attackers escalated defense evasion using a bring-your-own-vulnerable-driver (BYOVD) chain: three previously known vulnerable, signed kernel drivers (Topaz Antifraud wsftprm.sys / CVE-2023-52271, Tower of Fantasy GameDriverX64.sys / CVE-2025-61155, and K7 Security K7RKScan.sys / CVE-2025-1055) were abused to terminate protected security processes via crafted IOCTL requests, alongside a novel abuse of a Huawei HWAuidoOs2Ec.sys driver (documented publicly by Huntress only in March 2026, after this intrusion) and ABYSSWORKER -- a custom malicious driver, signed with likely-stolen certificates, that masquerades as a CrowdStrike Falcon driver and was first documented powering Medusa ransomware EDR-killing attacks.
The centerpiece of the intrusion is Backdoor.Turn, a Go-based remote access backdoor injected into the legitimate DbgView64.exe process. Backdoor.Turn requests an anonymous Microsoft Teams visitor token from Microsoft's Skype-backed identity services, uses that token to obtain credentials for a legitimate Microsoft TURN (Traversal Using Relays around NAT) relay server, and then tunnels a direct QUIC session to the attacker's real C2 server through that relay. Because the only traffic a network defender observes is an outbound connection to genuine Microsoft Teams/Skype infrastructure, the technique conceals the true C2 channel entirely within trusted collaboration-platform traffic. Symantec states this is the first known in-the-wild abuse of TURN relay infrastructure for C2 in this manner; the approach mirrors 'Ghost Calls,' a WebRTC/TURN-tunneling C2 technique against Zoom, Teams, and Google Meet publicly presented by Praetorian researcher Adam Crosser (open-sourced as the 'TURNt' tool) at Black Hat USA. Backdoor.Turn supports command execution, process creation, network/TLS-certificate/web-title scanning, LDAP and Active Directory searching, credential-based lateral movement, and browser credential theft.
For persistence and further defense evasion, the operators modified the LimitBlankPassword registry setting, created local backdoor accounts, and altered host firewall rules to permit their C2 communications. After roughly one to two months of dwell time, DragonForce deployed its ransomware payload, encrypting and exfiltrating victim data. DragonForce, active since June 2023, has since March 2025 operated as a formalized ransomware 'cartel' offering white-label branding to affiliates under its 'Ransom Bay' program, and by August-September 2025 had announced coordination partnerships with LockBit and Qilin -- evidence Symantec cites of the group's growing organizational maturity and technical sophistication.
Weaknesses (CWE)
CWE-400, CWE-862
Target sectors: professional services
Target regions: North America
Timeline
- DragonForce ransomware-as-a-service operation (tracked by Symantec as Hackledorb) begins operating.
- DragonForce rebrands as a ransomware 'cartel,' offering white-label affiliate branding under its 'Ransom Bay' model.
- DragonForce announces a cartel partnership with LockBit, taking a cut to handle encryptors, infrastructure, and negotiation portals for partners.
- DragonForce publicly announces a coordination partnership with Qilin and LockBit to share resources and dictate ransomware market conditions.
- Attackers gain access to a U.S. services firm's network, executing PowerShell commands to retrieve TechSupV18Fix3.zip from 192.36.27.51, a ZIP archive disguised as a tech-support hotfix.
- Operators DLL side-load a malicious vboxrt.dll alongside the legitimate VirtualBox/DbgView64.exe binary to run reconnaissance and detection-evasion code.
- Attackers deploy multiple BYOVD drivers (wsftprm.sys/CVE-2023-52271, GameDriverX64.sys/CVE-2025-61155, K7RKScan.sys/CVE-2025-1055, HWAuidoOs2Ec.sys, and ABYSSWORKER) to terminate protected security processes.
- Backdoor.Turn is injected into the legitimate DbgView64.exe process, establishing C2 by obtaining an anonymous Teams visitor token and tunneling a QUIC session through a legitimate Microsoft TURN relay.
- Attackers conduct LDAP/Active Directory enumeration, harvest browser-stored credentials, and move laterally across the victim network using stolen credentials.
- After roughly one to two months of dwell time, the DragonForce ransomware payload is deployed, encrypting and exfiltrating victim data.
- Huntress researchers publicly document the HWAuidoOs2Ec.sys Huawei driver vulnerability used in the intrusion, after the attack had already occurred.
- Symantec's Broadcom Threat Hunter Team publishes 'Hidden in Teams,' disclosing Backdoor.Turn and the Microsoft Teams TURN relay C2 evasion technique; Help Net Security and The Hacker News report on the findings the same day.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, CVE-2023-52271, CVE-2025-61155, CVE-2025-1055, T1190, T1059.001, T1136.001, T1574.001, T1685, T1686, T1112, T1036.005, T1027, T1555.003