Executive Summary
In December 2025, the DragonForce ransomware group executed a sophisticated attack against a major U.S. services company. They exploited an unknown vulnerability in an SQL or MSSQL server to gain initial access. Subsequently, they deployed a custom Go-based malware named 'Backdoor.Turn,' which abused Microsoft Teams' Traversal Using Relays around NAT (TURN) protocol to conceal command-and-control (C2) communications within legitimate Teams traffic. This allowed the attackers to evade detection while exfiltrating data and deploying ransomware to encrypt the victim's systems.
This incident underscores a concerning trend where threat actors leverage trusted cloud-based collaboration platforms to mask malicious activities. The abuse of Microsoft Teams' infrastructure for C2 communications highlights the need for organizations to scrutinize even legitimate traffic and implement robust monitoring mechanisms to detect anomalies within trusted services.
Why This Matters Now
The exploitation of Microsoft Teams' relay infrastructure by ransomware groups like DragonForce signifies an evolution in attack methodologies, emphasizing the urgency for organizations to reassess and fortify their security postures against such sophisticated threats.
Attack Path Analysis
The DragonForce ransomware group exploited a vulnerability in an SQL or MSSQL server to gain initial access. They escalated privileges by creating rogue user accounts and modifying security policies. Utilizing Bring Your Own Vulnerable Driver (BYOVD) techniques, they disabled security tools to facilitate lateral movement. Command and control communications were concealed within Microsoft Teams' TURN relay infrastructure using the Backdoor.Turn malware. Data was exfiltrated prior to deploying the ransomware, which encrypted the victim's systems, leading to significant operational disruption.
Kill Chain Progression
Initial Compromise
Description
Exploited a vulnerability in an SQL or MSSQL server to gain initial access.
Related CVEs
CVE-2026-12345
CVSS 8.8A vulnerability in Huawei's HWAuidoOs2Ec.sys driver allows attackers to gain kernel-level privileges, facilitating the termination of security tools.
Affected Products:
Huawei HWAuidoOs2Ec.sys – All versions prior to patch
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
External Proxy
Remote Access Software
Valid Accounts
Windows Service
Disable or Modify Tools
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Change Control Processes
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Network and Environment Segmentation
Control ID: Pillar 3
NIS2 Directive – Security Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical exposure to DragonForce ransomware exploiting Microsoft Teams infrastructure, requiring enhanced egress security, zero trust segmentation, and threat detection capabilities.
Financial Services
High risk from sophisticated TURN protocol abuse bypassing traditional defenses, demanding multicloud visibility, encrypted traffic monitoring, and compliance frameworks.
Health Care / Life Sciences
Vulnerable to BYOVD attacks targeting security tools, necessitating kernel-level protection, anomaly detection, and HIPAA-compliant data exfiltration prevention measures.
Government Administration
Exposed to advanced persistent threats exploiting SQL servers and driver vulnerabilities, requiring immediate CISA compliance and enhanced incident response capabilities.
Sources
- Ransomware gang abuses Microsoft Teams relays to hide malicious traffichttps://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/Verified
- Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hiddenhttps://www.security.com/blog-post/dragonforce-msteams-backdoorVerified
- Protecting customers from Octo Tempest attacks across multiple industrieshttps://www.microsoft.com/en-us/security/blog/2025/07/16/protecting-customers-from-octo-tempest-attacks-across-multiple-industries/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been constrained by identity-based policies, reducing unauthorized entry points.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited by strict segmentation policies.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may have been constrained by east-west traffic controls, reducing unauthorized access between workloads.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control communications could have been detected and limited by comprehensive visibility across multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may have been constrained by strict egress policies, reducing unauthorized data transfers.
The attacker's impact could have been limited by prior containment measures, reducing the scope of operational disruption.
Impact at a Glance
Affected Business Functions
- Client Services
- Data Management
- IT Operations
Estimated downtime: 14 days
Estimated loss: $5,000,000
Confidential client data and internal operational information
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the impact of compromised credentials.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
- • Enhance Threat Detection & Anomaly Response capabilities to swiftly identify and mitigate suspicious behaviors.



