DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2
DragonForce backdoors abuse Microsoft Teams TURN servers and (TL-2026-2836), also tracked as Backdoor.Turn, is a high-severity malware campaign, first published 2026-10-01. It is attributed to DragonForce (Malaysia) with medium confidence, affects Microsoft Microsoft Teams TURN relay infrastructure (abused legitimate, maps to 21 MITRE ATT&CK techniques (T1027, T1027.013, T1046), and is covered by 9 detection rules and 51 indicators of compromise.
Key facts for TL-2026-2836
- Threat ID
- TL-2026-2836
- Also known as
- Backdoor.Turn
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-10-01
- Last reviewed
- 2026-10-01
- Attribution
- DragonForce
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Malaysia
- Motivation
- FINANCIAL
- Target sectors
- services, technology
- Target regions
- North America
- Detection rules
- 9
- Indicators of compromise
- 51
Malware and tooling in DragonForce backdoors abuse Microsoft Teams TURN servers and
Malware and tooling: ABYSSWORKER, Backdoor.Turn, DragonForce, ADExplore
Lab52 reports DragonForce-linked backdoors that hide command-and-control in legitimate infrastructure: a Go-based Shell.dll injected in memory that abuses TURN (Microsoft Teams relays), and a javaw.exe/jli.dll sideloaded multi-stage loader for a second backdoor using MQTT. Both use DPAPI-bound payloads, scheduled-task persistence and encrypt their own memory while idle. Symantec's earlier Backdoor.Turn report ties the same TURN technique to a DragonForce ransomware intrusion that used BYOVD to kill security tools.
How DragonForce backdoors abuse Microsoft Teams TURN servers and works
On 2026-10-01 Lab52 published 'Backdoors in the dungeon: TURN & MQTT abused by DragonForce', documenting two custom backdoors attributed to the DragonForce ransomware-as-a-service (RaaS) operation (active since around 2023, since evolved into a cartel/infrastructure-provider model for affiliates). Lab52 relates the work to Symantec's earlier reporting on Backdoor.Turn (published 2026-06-16).
Backdoor 1 is a Go binary with metadata name Shell.dll that is injected directly into memory. It supports SSH-based communications authenticated with an embedded private key and abuses the TURN protocol for C2. The TURN channel uses messages of the form TRN1<UUID:16> with numeric command codes (22222222 C2 initiation; 33300000 task check, answered 'nocmd' when idle; 33299999 block download request; 3320 block retransmit; 33100000 task-receipt confirmation; 4440 beacon-to-C2 transfer initiation with blocks of up to 930 bytes; 4410 transfer status), with nonces generated via BCryptGenRandom. A TURN endpoint at 62.164.177.145:3478 is listed as an IOC.
Backdoor 2 is a multi-stage chain: the legitimate javaw.exe sideloads a malicious jli.dll (first-stage loader, three SHA256 variants published), which loads a DPAPI-encrypted, system-bound stage (rvsdiqw.txt) that runs the second backdoor. Staging payloads (25vtps.txt, dldwuibjn_chShllcodeTrn.txt/.bin) were fetched from http://188.190.4.111/. The second backdoor uses MQTT (described by Lab52 as a fallback channel) with a 16-character random session identifier, JSON commands validated by a 'cmdnum' field, and topic-based block retrieval with four-digit decimal indexes. Commands: cmdnum 1 inserts a URL (shk_url, tedByUID), cmdnum 2 runs a PowerShell line (ps_line, cmdid), cmdnum 3 executes a payload directly, cmdnum 4 inserts a remote host/port (rhost, rport). The MQTT endpoint 217.156.8.181:7586 is listed as an IOC.
Shared tradecraft: DLL sideloading via a legitimate executable, in-memory execution (CreateThread, VirtualProtect), XOR and Base64 payload obfuscation, DPAPI encryption that ties payloads to the host, scheduled-task persistence, and encryption of the memory region of the running code while sleeping (5-minute sleep before retry). Lab52 also lists several WordPress-hosted PHP endpoints (plus prolabgest.it) as IOCs; their precise role is not stated in the retrieved text.
Symantec (2026-06-16) analyzed Backdoor.Turn in a December 2025 DragonForce intrusion at a U.S. services company: a Go RAT that obtains an anonymous Teams visitor token from Microsoft's Skype-backed identity services, uses a legitimate Microsoft TURN relay, then runs a QUIC session to the real C2, so defenders see only outbound traffic to Microsoft. It was injected into DbgView64.exe and supports command execution, process creation, network scanning, TLS certificate capture, web page title collection, LDAP/Active Directory searching, credential-based lateral movement and browser credential theft. Symantec described it as the first known malware to abuse Teams TURN relays; the technique resembles Praetorian's 2025 'Ghost Calls' research on TURN credential hijacking. Initial access was likely an unknown SQL/MSSQL Server flaw (or an access broker). A PowerShell command pulled a ZIP (TechSupV18Fix3.zip from 192.36.27.51) containing legitimate VirtualBox/DbgView executables with malicious DLLs (vboxrt.dll) that fetched code from a list of C2 domains for recon, persistence and evasion. The actors modified LimitBlankPassword, added users/groups and altered firewall rules, used ADExplore and network scanners, and ran BYOVD to kill security tools with Huawei HWAuidoOs2Ec.sys ('Havoc Process Terminator'), Topaz Antifraud wsftprm.sys (CVE-2023-52271), Tower of Fantasy GameDriverx64.sys (CVE-2025-61155), K7 Security K7RKScan.sys (CVE-2025-1055) and a custom driver, ABYSSWORKER, masquerading as a Palo Alto driver. DragonForce ransomware was then deployed, with Backdoor.Turn reportedly installed afterwards for continued access. Dwell time was roughly 1-2 months. Press coverage links DragonForce to Scattered Spider; The Hacker News names the actor behind DragonForce as 'Hackledorb'. No CVE is assigned to the backdoors themselves; severity is analyst-assigned.
MITRE ATT&CK techniques used in TL-2026-2836
Defense Evasion
T1027 Obfuscated Files or Information; T1027.013 Encrypted/Encoded File; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1480.001 Environmental Keying; T1574.001 DLL; T1620 Reflective Code Loading
Discovery
T1046 Network Service Discovery; T1087.002 Domain Account
Persistence
T1053.005 Scheduled Task; T1136 Create Account
Execution
Command and Control
T1071 Application Layer Protocol; T1090.002 External Proxy; T1572 Protocol Tunneling
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools; T1686 Disable or Modify System Firewall
Credential Access
Affected products and versions in DragonForce backdoors abuse Microsoft Teams TURN servers and
- Microsoft — Microsoft Teams TURN relay infrastructure (abused legitimate service, not a vulnerability)
- Oracle — javaw.exe (legitimate Java launcher abused as DLL side-loading host)
- Microsoft — Windows (DPAPI-bound payloads, scheduled tasks)
- Microsoft — SQL Server (suspected initial access vector, unidentified flaw)
Remediation for DragonForce backdoors abuse Microsoft Teams TURN servers and
Immediate actions
- Hunt for javaw.exe loading jli.dll from a non-Java directory and for VirtualBox/DbgView executables loading vboxrt.dll from user-writable paths; block/quarantine the published SHA256 hashes
- Block outbound connections to 188.190.4.111, 62.164.177.145, 62.164.177.25, 217.156.8.181 and 192.36.27.51 and alert on the listed URLs and C2 domains
- Review scheduled tasks created by unexpected parents and investigate hosts with unexplained long-lived TURN (UDP/TCP 3478), QUIC or MQTT sessions
- Audit for LimitBlankPassword registry changes, unexpected new local accounts/groups and new firewall rules on hosts near internet-facing SQL Server
Workarounds
- Where Teams is not used, block Microsoft Teams relay endpoints at the egress proxy/firewall
Longer-term hardening
- Restrict outbound TURN/STUN and MQTT to approved services and baseline Teams relay use per host
- Deploy EDR with detection for DLL side-loading, in-memory injection and sleep-time memory encryption
- Harden internet-facing SQL Server instances and enforce a vulnerable-driver blocklist (HWAuidoOs2Ec.sys, wsftprm.sys, GameDriverx64.sys, K7RKScan.sys, ABYSSWORKER)
Timeline of DragonForce backdoors abuse Microsoft Teams TURN servers and
- DragonForce RaaS emerges (approximately 2023; exact date not specified), later evolving into a cartel-style/infrastructure-provider model for affiliates.
- DragonForce intrusion begins at a U.S. services company (month-level date): likely SQL/MSSQL Server exploitation, ZIP with sideloaded vboxrt.dll, BYOVD security-tool kill, recon with ADExplore; dwell time reportedly 1-2 months.
- Huntress documents abuse of the Huawei HWAuidoOs2Ec.sys driver (month-level date, after the Symantec-observed attack), per Symantec's reference to the technique.
- Symantec publishes 'Hidden in Teams' on Backdoor.Turn, the first known malware abusing Microsoft Teams TURN relays for C2 (Teams visitor token, TURN relay, QUIC session to real C2); BleepingComputer and Help Net Security cover it the same day.
- The Hacker News coverage of the Symantec/Carbon Black findings, including the BYOVD driver set and post-encryption Backdoor.Turn deployment.
- Threadlinqs hunt identifies the Lab52 report; IOCs and TTPs recorded for detection engineering.
- Lab52 publishes 'Backdoors in the dungeon: TURN & MQTT abused by DragonForce' with Shell.dll (TURN/SSH) and jli.dll/javaw.exe sideloaded MQTT backdoor analysis and IOCs.
Sources cited for DragonForce backdoors abuse Microsoft Teams TURN servers and
- Backdoors in the dungeon: TURN & MQTT abused by DragonForce (Lab52)
- Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden (Symantec)
- Ransomware gang abuses Microsoft Teams relays to hide malicious traffic (BleepingComputer)
- Cybercriminals mask malicious communications through Microsoft Teams relays (Help Net Security)
- DragonForce Hackers Abuse Microsoft Teams Relays (The Hacker News)
- DragonForce ransomware backdoor weaponises legit Microsoft Teams servers (Techfinitive)
- DragonForce Hackers Exploit Microsoft Teams TURN Relays to Conceal Backdoor.Turn C2 (Rescana)
- Ransomware Operators Use Microsoft Teams Servers to Hide Their Traffic (Hackmag)
- How DragonForce Weaponized Microsoft Teams to Outlast Its Own Ransomware (Security Buzz)
More in malware
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
Detection coverage for TL-2026-2836
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2836 across Splunk SPL, Microsoft KQL and Sigma, covering 51 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2836
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.