DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic: A Deep Dive into Cybercrime
The world of cybercrime is a complex and ever-evolving landscape, and the recent discovery of DragonForce hackers exploiting Microsoft Teams relays to conceal their command-and-control (C2) traffic is a fascinating insight into the tactics employed by these malicious actors.
In my opinion, this attack highlights the sophistication and adaptability of cybercriminals, who are constantly finding new ways to bypass security measures and maintain access to compromised systems. The use of Microsoft Teams relays as a cover for C2 traffic is a clever and subtle approach, one that showcases the attackers' understanding of legitimate network infrastructure.
What makes this incident particularly intriguing is the attackers' ability to exploit vulnerabilities in SQL or MS-SQL servers, as well as the potential involvement of initial access brokers (IABs). The initial malicious activity, which began in December 2025, involved a PowerShell command to drop a ZIP archive, which then launched a DLL side-loading attack. This attack technique, known as bring your own vulnerable driver (BYOVD), is a powerful tool in the hands of cybercriminals.
The use of the 'DbgView64.exe' process to inject the Backdoor.Turn malware is a strategic move, suggesting that the attackers are aiming to maintain long-term access to the compromised host. This is a common tactic in ransomware attacks, where the malware is often designed to remain on the system, allowing for further exploitation and data exfiltration.
One of the most interesting aspects of this attack is the utilization of Microsoft's Traversal Using Relays around NAT (TURN) relay infrastructure. By leveraging legitimate Microsoft servers as TURN relays, the attackers can set up connections that appear entirely legitimate to network defenders. This stealthy approach, combined with the Ghost Calls technique, allows the attackers to exfiltrate data covertly, leaving victims unaware of the ongoing attack.
The broader implications of this attack are significant. The DragonForce threat actor, Hackledorb, has evolved from a conventional ransomware-as-a-service (RaaS) model to a highly organized and formalized cartel structure. This shift in tactics indicates a more sophisticated and persistent group, one that is constantly developing new capabilities and exploiting advanced techniques.
In my view, this attack serves as a stark reminder of the ongoing arms race between cybercriminals and cybersecurity professionals. As defenders strive to stay ahead, the attackers are equally determined to find new ways to bypass security measures. The use of legitimate infrastructure for malicious purposes highlights the need for constant vigilance and innovative security solutions.
This incident also underscores the importance of understanding the tactics and techniques employed by cybercriminals. By studying these attacks, security researchers and practitioners can better prepare for and mitigate future threats. The ability to identify and analyze these sophisticated cyber operations is crucial in the ongoing battle against cybercrime.
In conclusion, the DragonForce hackers' abuse of Microsoft Teams relays to hide Backdoor.Turn C2 traffic is a fascinating and complex cybercrime incident. It showcases the attackers' adaptability, understanding of legitimate infrastructure, and ability to exploit vulnerabilities. As the cyber landscape continues to evolve, it is essential to remain informed and proactive in the face of these ever-changing threats.