Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1471+ Articles
151+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. DragonForce Ransomware Hides C2 Traffic Inside Microsoft Teams Relays
DragonForce Ransomware Hides C2 Traffic Inside Microsoft Teams Relays
NEWS

DragonForce Ransomware Hides C2 Traffic Inside Microsoft Teams Relays

DragonForce ransomware operators deployed a custom implant called Backdoor.Turn to camouflage command-and-control communications inside legitimate Microsoft Teams relay infrastructure, evading network-based detection.

Dylan H.

News Desk

June 16, 2026
3 min read

DragonForce Ransomware Tunnels C2 Through Teams Infrastructure

The DragonForce ransomware group has developed a novel evasion technique: tunneling its command-and-control (C2) communications through Microsoft Teams relay infrastructure using a custom malware implant named Backdoor.Turn. By disguising malicious traffic as legitimate Teams traffic, the group can operate inside enterprise networks while bypassing firewall rules and deep packet inspection tools that would otherwise flag suspicious outbound connections.


Backdoor.Turn — The Evasion Implant

Backdoor.Turn is a custom-written backdoor designed specifically to abuse Microsoft Teams' relay architecture. Key characteristics:

AttributeDetail
Malware nameBackdoor.Turn
Threat actorDragonForce ransomware group
TechniqueC2 tunneling via Teams relay WebSockets
TargetsEnterprise networks running Microsoft 365 / Teams
GoalPersistent access while evading network-based detection

How the Evasion Works

Microsoft Teams uses a relay infrastructure to route calls, chats, and media through Microsoft-operated servers when direct peer-to-peer connections are not possible. Backdoor.Turn abuses this mechanism:

  1. Initial compromise — The implant is deployed on an already-compromised host via DragonForce's standard intrusion chain
  2. Protocol mimicry — Backdoor.Turn crafts traffic that conforms to Teams' WebSocket-based relay protocol
  3. C2 tunneling — Attacker commands and victim data are encoded and transmitted inside what appears to be Teams relay traffic
  4. Firewall bypass — Corporate firewalls typically allowlist Teams relay endpoints (e.g., *.teams.microsoft.com), so the malicious traffic passes through uninspected

Why This Matters

Most enterprise network defenses are configured to trust Microsoft 365 infrastructure by default. Security policies routinely allow broad traffic to Teams relay servers because blocking them would disable a critical business communication tool. DragonForce exploits this trusted status to maintain persistent access without triggering alerts.

Detection Challenges

  • No suspicious destination IPs — Traffic terminates at legitimate Microsoft servers
  • Encrypted payload — HTTPS/WSS encryption conceals the actual C2 commands
  • Normal traffic patterns — Teams usage is expected on corporate networks, masking volume anomalies

DragonForce Background

DragonForce is an active ransomware-as-a-service (RaaS) operation known for:

  • Double extortion (encrypting files and threatening to leak stolen data)
  • Targeting manufacturing, retail, and critical infrastructure sectors
  • Developing sophisticated custom tooling to extend dwell time

The introduction of Backdoor.Turn demonstrates continued investment in detection evasion, allowing DragonForce affiliates to maintain access for extended periods before deploying the ransomware payload.


Defensive Recommendations

  1. Monitor Teams relay traffic anomalies — Unusual volumes from non-Teams processes connecting to Teams relay endpoints should trigger investigation
  2. Endpoint detection — Deploy EDR solutions capable of inspecting process behavior, not just network destinations; look for non-Teams binaries establishing connections to Teams relay servers
  3. Zero Trust network segmentation — Limit which hosts can initiate outbound connections to Teams infrastructure
  4. Behavioral baselines — Establish normal Teams traffic baselines per host and alert on deviations
  5. Hunt for Backdoor.Turn IOCs — Work with your threat intelligence provider for current indicators of compromise

Indicators of Compromise

Contact your threat intelligence provider or search current threat feeds for Backdoor.Turn indicators. IOCs include:

  • Non-teams.exe / non-msedgewebview2.exe processes making WebSocket connections to *.relay.teams.microsoft.com
  • Unusual persistence mechanisms (registry run keys, scheduled tasks) associated with new, unsigned binaries
  • Large volumes of outbound encrypted traffic from workstations at unusual hours

Sources

  • BleepingComputer — Ransomware gang abuses Microsoft Teams relays to hide malicious traffic

Related Reading

  • Kongtuke Hackers Now Use Microsoft Teams for Corporate Breaches
  • The Gentlemen Ransomware Now Uses SystemBC for Bot-Powered Attacks
  • AI-Built Ransomware Toolkit Automates EDR Evasion, AD Discovery
#Ransomware#Malware#Microsoft#DragonForce#C2 Evasion#Cybercrime

Related Articles

Cybercrime Service Disrupted for Abusing Microsoft Platform

Microsoft has disrupted a malware-signing-as-a-service operation that exploited the company's Artifact Signing service to produce fraudulent code-signing...

4 min read

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

A new analysis of The Gentlemen ransomware operation reveals the financially motivated group has claimed 478 victims and evolved a worm-like...

4 min read

Infostealers Turn Millions of Devices Into Credential Theft Machines

Attackers increasingly favor stolen credentials over exploits, and infostealers have become the primary access broker feeding ransomware and cybercrime...

6 min read
Back to all News