ransomware DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic A U.S. services firm was targeted by the DragonForce ransomware group, who utilized a custom Go-based RAT, Backdoor.Turn, to conceal C2 traffic within Microsoft Teams relay infrastructure. The attackers leveraged a BYOVD technique, deploying a malicious driver and conducting reconnaissance, ultimately aiming to maintai… The Hacker News · Jun 18, 2026 High CVE-2023-52271CVE-2025-61155CVE-2025-1055USturnbyovdghost calls
ransomware Ransomware gang abuses Microsoft Teams relays to hide malicious traffic DragonForce ransomware utilized a custom malware, Backdoor.Turn, to conceal command-and-control traffic by leveraging Microsoft Teams’ TURN protocol. This technique allowed the attackers to bypass traditional network def… BleepingComputer · Jun 16, 2026 High CVE-2023-52271CVE-2025-61155CVE-2025-1055USteamsturnrat