• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Sq Magazine LogoSQ Magazine

Smarter Insights for a Fast-Moving Digital World

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Sq Magazine Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cybersecurity

Hackers Abuse Microsoft Teams to Conceal Ransomware Activity

Published on: June 16, 2026
Sofia Ramirez
Written By
Sofia Ramirez
Sofia Ramirez
Senior Tech Writer • 434 Articles
Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps reader...
LATEST POSTS:
FBI Destroys Massive AI Phishing Empire Linked to $1.9B Theft
ShinyHunters Targets Council of Europe in Major Cyberattack
What Is Phishing? How It Works, Types, and How to Spot It in 2026
Robert A. Lee
Reviewed By
Robert A. Lee
Robert A. Lee
Senior Editor • 380 Articles
Robert A. Lee is a journalist at SQ Magazine who unpacks the fast-moving worlds of gaming and internet trends. He tracks everything from maj...
LATEST POSTS:
YouTube vs TikTok Statistics 2026: Users, Revenue, Creator Economy
Facebook and Instagram Hit by Major Global Outage
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Hackers Abuse Microsoft Teams To Conceal Ransomware
As Featured In
The New York Times LogoForbes LogoWired LogoDeloitte LogoResearch.com Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

Cybersecurity researchers have uncovered a sophisticated DragonForce ransomware attack in which hackers used Microsoft Teams infrastructure to hide malicious communications and evade detection.

Quick Summary – TLDR:

  • DragonForce ransomware operators used a custom malware called Backdoor.Turn to conceal command and control traffic.
  • The malware abused Microsoft Teams TURN relay infrastructure, making malicious activity appear as legitimate Teams traffic.
  • Researchers say this is the first known real world case of malware exploiting Teams relays for command and control communications.
  • The attack also featured advanced defense evasion techniques, including vulnerable driver exploitation and custom malware tools.

What Happened?

Researchers at Symantec have detailed a highly sophisticated DragonForce ransomware campaign targeting a major U.S. services company. The attackers used a previously unseen remote access trojan called Backdoor.Turn that leveraged Microsoft Teams relay infrastructure to disguise communications with attacker controlled servers.

Because the traffic appeared to be associated with legitimate Microsoft Teams services, security teams had little visibility into the malicious activity occurring within the victim’s network.

#NEW – Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden – To our knowledge this is the first time TURN relay infrastructure has been abused this way in the wild. Read more: https://t.co/i6s0iVisxc pic.twitter.com/V4vKRIcdwj

— Threat Intelligence (@threatintel) June 16, 2026

Attackers Hid Malicious Traffic Inside Microsoft Teams

The most significant aspect of the attack was the use of Backdoor.Turn, a custom Go based remote access backdoor designed to blend malicious traffic with trusted Microsoft services.

The malware obtains an anonymous Teams visitor token through Microsoft’s Skype backed identity services and uses a legitimate Microsoft TURN relay server during connection setup. Once the connection is established, the malware creates a QUIC session with the attackers’ command and control infrastructure.

As a result, defenders monitoring network activity would only observe connections to legitimate Microsoft Teams servers rather than attacker controlled systems.

According to Symantec:

“

Backdoor.Turn, a Go-based RAT, is the first known malware to abuse Microsoft Teams’ TURN relay servers to mask command-and-control traffic.

Symantec

Researchers noted that while the concept was demonstrated in 2025 through Praetorian’s Ghost Calls research, this is the first documented case of threat actors using the technique in a real attack.

DragonForce Maintained Access for Weeks

The attack began in December 2025 and appears to have started through the exploitation of an unknown vulnerability in an SQL or MSSQL server. Researchers also noted that access may have been acquired through an access broker.

Once inside the network, the attackers deployed a ZIP archive containing a legitimate VirtualBox and DbgView executable alongside a malicious DLL file. Through DLL side loading and DLL hijacking techniques, the attackers were able to execute malicious code while appearing legitimate.

The threat actors remained inside the victim environment for approximately one to two months, carrying out reconnaissance, persistence activities, and defense evasion before deploying ransomware.

To strengthen their foothold, the attackers:

  • Created rogue user accounts.
  • Modified firewall rules.
  • Used the Windows LimitBlankPassword policy to simplify future access.
  • Established multiple methods of persistence across compromised systems.
Newsletter
Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.

Advanced Defense Evasion Techniques

The campaign showcased a high level of technical sophistication through the use of Bring Your Own Vulnerable Driver (BYOVD) techniques.

The attackers exploited several signed but vulnerable drivers to gain kernel level privileges and disable security software. These included:

  • Huawei HWAuidoOs2Ec.sys
  • Topaz Antifraud wsftprm.sys
  • Tower of Fantasy Gamedriverx64.sys
  • K7 Security K7RKScan.sys

Researchers highlighted a particularly notable technique called Havoc Process Terminator, which leveraged Huawei’s HWAuidoOs2Ec.sys driver in a manner not previously observed in real world attacks.

The group also deployed ABYSSWORKER, a custom malicious driver disguised as a legitimate Palo Alto Networks driver. Unlike traditional BYOVD attacks that rely on vulnerable legitimate drivers, ABYSSWORKER was specifically built for malicious purposes.

Backdoor.Turn Offered Broad Espionage Capabilities

Backdoor.Turn was injected into the legitimate DbgView64.exe process, helping it remain hidden from security tools.

The malware provided attackers with extensive capabilities, including:

  • Command execution and process creation.
  • Network scanning and reconnaissance.
  • TLS certificate collection.
  • Website title harvesting.
  • LDAP and Active Directory searches.
  • Browser credential theft.
  • Credential based lateral movement.

Researchers believe the malware was deployed after ransomware execution, suggesting it may have been intended to maintain long term access or potentially be resold to other cybercriminal groups.

DragonForce Continues to Evolve

DragonForce has been active since at least 2023 and has evolved from a traditional ransomware as a service operation into a more structured cartel style organization. The group has also been linked to the notorious Scattered Spider threat ecosystem.

Researchers said the campaign demonstrates an exceptional level of expertise and operational maturity. The combination of custom malware development, advanced defense evasion techniques, and abuse of trusted enterprise infrastructure highlights the growing sophistication of modern ransomware operations.

SQ Magazine Takeaway

I think this attack is a warning sign for security teams everywhere. For years, defenders have focused on spotting suspicious domains and unusual network connections. DragonForce showed that attackers can now hide inside services organizations trust every day. When malicious traffic looks exactly like Microsoft Teams traffic, traditional monitoring becomes much less effective. This campaign demonstrates how quickly ransomware groups are innovating, and why organizations must move beyond simple network based detection to identify advanced threats.

This article has been reviewed and fact-checked by Robert A. Lee. SQ Magazine follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add SQ Magazine as a Preferred Source on Google for updates! Follow on Google News
Share ChatGPT Perplexity

References

  • Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden
Sofia Ramirez

Sofia Ramirez

Senior Tech Writer


Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps readers stay informed and secure in today’s fast-changing tech landscape. Passionate about making cybersecurity accessible, Sofia blends research-driven analysis with straightforward explanations; so whether you’re a tech professional or a curious reader, her work ensures you’re always one step ahead in the digital world.

Related Posts

Sarvam Becomes AI Unicorn After Massive $234M Funding Round
Artificial Intelligence

Sarvam Becomes AI Unicorn After Massive $234M Funding Round

Anthropic Introduces Age Checks and ID Verification for Claude
Artificial Intelligence

Anthropic Introduces Age Checks and ID Verification for Claude

FBI Destroys Massive AI Phishing Empire Linked to $1.9B Theft
Cybersecurity

FBI Destroys Massive AI Phishing Empire Linked to $1.9B Theft

Disclaimer: The content published on SQ Magazine is for informational and educational purposes only. Please verify details independently before making any important decisions based on our content.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

ShinyHunters Targets Council of Europe in Major Cyberattack
What Is Phishing? How It Works, Types, and How to Spot It in 2026
Urgent Oracle PeopleSoft Flaw Linked to ShinyHunters Campaign

Table of Contents

  • Quick Summary – TLDR:
  • What Happened?
  • Attackers Hid Malicious Traffic Inside Microsoft Teams
  • DragonForce Maintained Access for Weeks
  • Advanced Defense Evasion Techniques
  • Backdoor.Turn Offered Broad Espionage Capabilities
  • DragonForce Continues to Evolve
  • SQ Magazine Takeaway
Connect on Telegram

Footer

SQ Magazine Logo

Smarter Insights for a Fast-Moving Digital World

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer

Worth Checking

  • Social Media Attention Span Stats
  • Reddit Statistics
  • Spotify User Statistics
  • TikTok vs. Instagram Statistics
  • Gen Z Social Media Statistics
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.

  • Privacy Policy
  • Terms
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • Brand Assets
    Brand Assets
  • Stats Methodology
    Stats Research Process
  • Glossary
    Glossary
Categories
  • Internet
  • Gaming
  • Technology
  • Artificial Intelligence
  • Cybersecurity
Internet
YouTube vs TikTok Statistics 2026: Users, Revenue, Creator Economy
YouTube vs TikTok Statistics 2026: Users, Revenue, Creator Economy
Internet Outage Statistics 2026: Frequency, Cost and Causes
Internet Outage Statistics 2026: Frequency, Cost and Causes
Upwork Statistics 2026: Revenue, GSV, AI Work
Upwork Statistics 2026: Revenue, GSV, AI Work
Instagram Reels Statistics 2026: Plays and Engagement
Instagram Reels Statistics 2026: Plays and Engagement
Gig Economy Statistics 2026: Workforce & Earnings
Gig Economy Statistics 2026: Workforce & Earnings
Doomscrolling Statistics: Prevalence, Sleep and Mental Health
Doomscrolling Statistics: Prevalence, Sleep and Mental Health
Gaming
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Apex Legends Statistics 2026: Players, Revenue, and Esports
Apex Legends Statistics 2026: Players, Revenue, and Esports
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Gamers Statistics 2026: Players, Habits & Global Data
Gamers Statistics 2026: Players, Habits & Global Data
Minecraft Statistics 2026: 300 Million Copies Sold & 212M Monthly Players
Minecraft Statistics 2026: 300 Million Copies Sold & 212M Monthly Players
Technology
Employee Productivity Statistics 2026: Engagement, Costs & Trends
Employee Productivity Statistics 2026: Engagement, Costs & Trends
Software Engineer Layoff Statistics 2026: Companies, Roles, AI Impact
Software Engineer Layoff Statistics 2026: Companies, Roles, AI Impact
iPhone Ecosystem Statistics 2026: Big Market Trends
iPhone Ecosystem Statistics 2026: Big Market Trends
Average Screen Time by Age Statistics 2026: Latest Insights
Average Screen Time by Age Statistics 2026: Latest Insights
AI SEO Statistics 2026: Adoption, AI Overviews & LLM Citation Data
AI SEO Statistics 2026: Adoption, AI Overviews & LLM Citation Data
Digital Nomads Statistics 2026: Population, Demographics & Visa Data
Digital Nomads Statistics 2026: Population, Demographics & Visa Data
Artificial Intelligence
AI Image Generation Statistics 2026: Market Size, Adoption & Risks
AI Image Generation Statistics 2026: Market Size, Adoption & Risks
AI Influencer Marketing Statistics: Market Size and Engagement
AI Influencer Marketing Statistics: Market Size and Engagement
AI Market Statistics 2026: Size, Growth & Investment
AI Market Statistics 2026: Size, Growth & Investment
Meta AI Statistics 2026: Users, Capex, and Adoption Data
Meta AI Statistics 2026: Users, Capex, and Adoption Data
Predictive AI Statistics 2026: Market Size, Adoption & Accuracy Data
Predictive AI Statistics 2026: Market Size, Adoption & Accuracy Data
AI Overviews Statistics 2026: Google Search Impact Data
AI Overviews Statistics 2026: Google Search Impact Data
Cybersecurity
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Identity Theft Statistics 2026: Key Fraud Data and Trends
Identity Theft Statistics 2026: Key Fraud Data and Trends
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
API Security Breach Statistics 2026: Hidden Threats
API Security Breach Statistics 2026: Hidden Threats
AI Voice Cloning Fraud Statistics 2026: Alarming Trends You Must Know Now
AI Voice Cloning Fraud Statistics 2026: Alarming Trends You Must Know Now
Categories
  • Internet
  • Gaming
  • Technology
  • Artificial Intelligence
  • Cybersecurity
Internet
Facebook and Instagram Hit by Major Global Outage
Facebook and Instagram Hit by Major Global Outage
Pinterest Bets Big on AI With Record $4B AWS Commitment
Pinterest Bets Big on AI With Record $4B AWS Commitment
Lovable Expands Google Cloud Deal, Boosts AI Infrastructure 5x
Lovable Expands Google Cloud Deal, Boosts AI Infrastructure 5x
Shopify Down: Thousands Report Outage and Checkout Issues
Shopify Down: Thousands Report Outage and Checkout Issues
Microsoft Investigates Teams and Office File Access Outage
Microsoft Investigates Teams and Office File Access Outage
Microsoft Confirms MFA Issues and My Sign Ins Downtime
Microsoft Confirms MFA Issues and My Sign Ins Downtime
Gaming
Epic Games Teases Unreal Engine 6 for Rocket League
Epic Games Teases Unreal Engine 6 for Rocket League
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Battlefield 6 Outperforms Franchise Past with Record-Breaking Launch
Battlefield 6 Outperforms Franchise Past with Record-Breaking Launch
Technology
Telegram Returns to Wear OS With Smartwatch App Upgrade
Telegram Returns to Wear OS With Smartwatch App Upgrade
Apple Announces macOS 27 Golden Gate at WWDC 2026
Apple Announces macOS 27 Golden Gate at WWDC 2026
Apple iPadOS 27 Introduces New Siri App and Productivity Tools
Apple iPadOS 27 Introduces New Siri App and Productivity Tools
Microsoft Reveals Xbox Series X25 Limited Edition Console
Microsoft Reveals Xbox Series X25 Limited Edition Console
Leaked iOS 27 Features Include AI Siri and More iPhone Support
Leaked iOS 27 Features Include AI Siri and More iPhone Support
iPhone 18 Pro Max Leak Reveals No Change in Thickness
iPhone 18 Pro Max Leak Reveals No Change in Thickness
Artificial Intelligence
Sarvam Becomes AI Unicorn After Massive $234M Funding Round
Sarvam Becomes AI Unicorn After Massive $234M Funding Round
Anthropic Introduces Age Checks and ID Verification for Claude
Anthropic Introduces Age Checks and ID Verification for Claude
New Kimi K2.7 Code Promises Faster AI Coding Workflows
New Kimi K2.7 Code Promises Faster AI Coding Workflows
US Blocks Anthropic Fable 5 Access Over Security Fears
US Blocks Anthropic Fable 5 Access Over Security Fears
McDonald’s Tests Powerful New AI Drive Thru With Google
McDonald’s Tests Powerful New AI Drive Thru With Google
Anthropic Launches Claude Fable 5, Its Most Powerful AI Model Yet
Anthropic Launches Claude Fable 5, Its Most Powerful AI Model Yet
Cybersecurity
Hackers Abuse Microsoft Teams to Conceal Ransomware Activity
Hackers Abuse Microsoft Teams to Conceal Ransomware Activity
FBI Destroys Massive AI Phishing Empire Linked to $1.9B Theft
FBI Destroys Massive AI Phishing Empire Linked to $1.9B Theft
ShinyHunters Targets Council of Europe in Major Cyberattack
ShinyHunters Targets Council of Europe in Major Cyberattack
Urgent Oracle PeopleSoft Flaw Linked to ShinyHunters Campaign
Urgent Oracle PeopleSoft Flaw Linked to ShinyHunters Campaign
73,000 French Government Accounts Exposed in Tchap Breach
73,000 French Government Accounts Exposed in Tchap Breach
High Risk Microsoft Teams Android Bug Could Leak Sensitive Data
High Risk Microsoft Teams Android Bug Could Leak Sensitive Data
Newsletter

Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.

Newsletter

Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.