The Containment Era is here. →Explore

Executive Summary

In December 2025, the DragonForce ransomware group executed a sophisticated attack against a major U.S. services company. They exploited an unknown vulnerability in an SQL or MSSQL server to gain initial access. Subsequently, they deployed a custom Go-based malware named 'Backdoor.Turn,' which abused Microsoft Teams' Traversal Using Relays around NAT (TURN) protocol to conceal command-and-control (C2) communications within legitimate Teams traffic. This allowed the attackers to evade detection while exfiltrating data and deploying ransomware to encrypt the victim's systems.

This incident underscores a concerning trend where threat actors leverage trusted cloud-based collaboration platforms to mask malicious activities. The abuse of Microsoft Teams' infrastructure for C2 communications highlights the need for organizations to scrutinize even legitimate traffic and implement robust monitoring mechanisms to detect anomalies within trusted services.

Why This Matters Now

The exploitation of Microsoft Teams' relay infrastructure by ransomware groups like DragonForce signifies an evolution in attack methodologies, emphasizing the urgency for organizations to reassess and fortify their security postures against such sophisticated threats.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

DragonForce used a custom malware called 'Backdoor.Turn' to abuse Microsoft Teams' TURN protocol, concealing their command-and-control communications within legitimate Teams traffic.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's initial access may have been constrained by identity-based policies, reducing unauthorized entry points.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could have been limited by strict segmentation policies.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement may have been constrained by east-west traffic controls, reducing unauthorized access between workloads.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's command and control communications could have been detected and limited by comprehensive visibility across multicloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's data exfiltration efforts may have been constrained by strict egress policies, reducing unauthorized data transfers.

Impact (Mitigations)

The attacker's impact could have been limited by prior containment measures, reducing the scope of operational disruption.

Impact at a Glance

Affected Business Functions

  • Client Services
  • Data Management
  • IT Operations
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Confidential client data and internal operational information

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement and limit the impact of compromised credentials.
  • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
  • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
  • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
  • Enhance Threat Detection & Anomaly Response capabilities to swiftly identify and mitigate suspicious behaviors.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image