{
  "name": "Attackers Weaponize Microsoft Teams Relays to Stay Hidden",
  "slug": "attackers-weaponize-microsoft-teams-relays-to-stay-hidden",
  "description": "Attackers deploying DragonForce ransomware against a major U.S. services firm concealed their command-and-control traffic within Microsoft Teams relay infrastructure using Backdoor.Turn, a custom Go-based remote access trojan. This novel technique leverages anonymous Teams visitor tokens and TURN relay servers to mask malicious communications as legitimate Microsoft traffic. The intrusion lasted one to two months, beginning in December 2025 with exploitation of an SQL server vulnerability. Attackers employed sophisticated defense evasion tactics including DLL side-loading with VirtualBox executables and multiple Bring Your Own Vulnerable Driver techniques. They exploited a previously unknown vulnerability in Huawei's HWAuidoOs2Ec.sys driver, along with several other vulnerable drivers, to terminate security processes at kernel level. The campaign demonstrates DragonForce's evolution into a highly capable ransomware cartel with advanced operational maturity.",
  "published": "2026-06-16T14:44:33.091000+00:00",
  "created_at": "2026-06-16T17:49:18.103000+00:00",
  "modified_at": "2026-06-16T15:49:18+00:00",
  "created_at_opencti": "2026-06-16T17:49:18.103000+00:00",
  "author": "AlienVault",
  "confidence": 100,
  "report_types": [
    "threat-report"
  ],
  "labels": [
    "backdoor.turn",
    "byovd",
    "credential theft",
    "cve-2023-52271",
    "cve-2025-1055",
    "cve-2025-61155",
    "dll side-loading",
    "dragonforce",
    "microsoft teams abuse",
    "ransomware",
    "turn relay",
    "vulnerable drivers"
  ],
  "tags": [
    "2026-06-16",
    "CVE-2023-52271",
    "CVE-2025-1055",
    "CVE-2025-61155",
    "backdoor.turn",
    "byovd",
    "credential-theft",
    "dll side-loading",
    "dragonforce",
    "microsoft teams abuse",
    "ransomware",
    "turn relay",
    "vulnerable drivers"
  ],
  "related_entities": {
    "vulnerabilities": [
      {
        "id": "c7d7a665-5f3f-441e-8f23-d028ebfc34da",
        "name": "CVE-2025-61155"
      },
      {
        "id": "1a7f7e25-7c3a-4c34-ab91-625fe573b7e1",
        "name": "CVE-2025-1055"
      },
      {
        "id": "e9c6bb28-d2b8-4819-a2e8-fcb39234827e",
        "name": "CVE-2023-52271"
      }
    ],
    "indicators": [
      {
        "id": "34234e56-6892-4621-b3d4-d59eff62372c",
        "name": "ce66b8221446c9b6d83f0ce6382f430e519601641e5daaaf1ca7a8a8806cb0b0"
      },
      {
        "id": "9c078ccf-fb87-4af6-85de-6ac697616507",
        "name": "9335f61f8ad276d94455c5b6876fea48152c3cea759f2598c8108ee461fa5759"
      },
      {
        "id": "63edb3f7-4f56-471a-98ef-f252a5a9f101",
        "name": "e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22"
      },
      {
        "id": "0c8e7dc5-3ad4-45fe-8974-3fbd994e43ac",
        "name": "aea26980059ef2ad11e99556a4edfa1f8ec769fa9f06aa573b81bedf319954b5"
      },
      {
        "id": "46da42f8-197f-46b2-8eeb-ce0c080df385",
        "name": "6f9fbe29f8cc2788e2bc9d631e0eea2a8e9837076837b55838005a0e654f0a9e"
      },
      {
        "id": "c009e04e-505a-4dc4-bb9c-74cf8c87b7e6",
        "name": "projetosmecanicos.com.br"
      },
      {
        "id": "edbb5c7e-656f-47b9-a8f8-5d1f83663be7",
        "name": "6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4"
      },
      {
        "id": "002d3ec7-231b-4d30-a029-c28d269fd72c",
        "name": "http://192.36.27.51/TechSupV18Fix3.zip"
      },
      {
        "id": "1735fd5c-09e3-4434-89da-3f67986a8fc9",
        "name": "f174c19902523dcf005fa044b6598403a5e5c0a5982398d1bc0dcc5ec1cd351b"
      },
      {
        "id": "5420d0b3-0233-442c-b241-a91d3cbf57e4",
        "name": "glanz-gmbh.de"
      },
      {
        "id": "19142592-3853-48c6-ad56-250c5ecc515c",
        "name": "cd078957167e1af4de39aecdb981cd14156fa81d5a9c6ac51e74ae5b6199a12a"
      },
      {
        "id": "dafa3b1b-3821-498a-a391-cc4069e7bf7c",
        "name": "65ab49119c845801f29a57e8aa177146b2ffbd289d4278109b146f933380f951"
      },
      {
        "id": "f52f4698-2124-4ef3-9043-fc64417785e7",
        "name": "82b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013b"
      },
      {
        "id": "49e98155-ad9e-4bf1-a3dc-cd2db113682d",
        "name": "821da79d727351dd67ce5df7950e9a3de6647a3cf474bb3a093f67507fed92a6"
      },
      {
        "id": "f886b549-c924-4b18-a613-d8ffa1ea1ffd",
        "name": "d20a3c928761fe00ac522eeb474612b5804cd9108453ea8591106d5d4428428e"
      },
      {
        "id": "63d2d0e1-4c0b-42cc-ab99-7a8ce1eff738",
        "name": "8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2"
      },
      {
        "id": "58211f43-85fa-441b-8fad-26257a9d6951",
        "name": "d0da2832ae1e13a98f7ce7e33a66c1b0d9797b81f69ece134e4462ea55ac923e"
      },
      {
        "id": "adf45a48-5d51-4b0f-bb93-e4961fa7171f",
        "name": "mysimerp.net"
      },
      {
        "id": "6746b8bb-c74c-49b8-b7fb-0187d00e5fa2",
        "name": "8a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c5531"
      },
      {
        "id": "68c78a2e-dfe6-4c73-84c6-2c8e4b6c921e",
        "name": "professionalhomebasedbusiness.com"
      },
      {
        "id": "55851dce-cba7-424a-9119-08e611d2ed2f",
        "name": "62.164.177.25"
      },
      {
        "id": "8d426027-a9c1-49d5-8027-6525d81fa724",
        "name": "safefire.jo"
      },
      {
        "id": "7754a489-f963-4668-91cc-ea82fbf1e4c8",
        "name": "socialbizsolutions.com"
      },
      {
        "id": "1fed76b9-7749-4403-8397-e285f9a90fa8",
        "name": "048e18416177de2ead251abdf4d89837f6807c6aba4d5b1debe49adfdecbf05c"
      },
      {
        "id": "68c6b82d-d1c1-401d-9f60-bb06df6ad09b",
        "name": "turnkeyaiagents.com"
      },
      {
        "id": "5671fe4a-3762-449b-830a-639f86de8383",
        "name": "comunidadesparentais.com.br"
      }
    ],
    "intrusion_sets": [
      {
        "id": "a63d97b5-8199-4473-a37a-2ef8956ad332",
        "name": "DragonForce",
        "slug": "dragonforce"
      }
    ],
    "attack_patterns": [
      {
        "id": "a706defa-5a99-4a26-b1be-ac6c1fc20b92",
        "name": "T1562.006"
      },
      {
        "id": "74d6e294-54d1-4a21-9dfc-df5870f8ec8e",
        "name": "T1003"
      },
      {
        "id": "9e6c4b38-f4e1-4b1f-b90a-222f881acbab",
        "name": "T1087.002"
      },
      {
        "id": "c3af9fd7-d307-4df4-9220-cc627938fb85",
        "name": "T1055"
      },
      {
        "id": "b7ba0db0-7d4f-436f-8d5f-c431d690b048",
        "name": "T1555.003"
      },
      {
        "id": "c9ee9b30-ba84-4c24-95e9-e8242d42af3f",
        "name": "T1071.001"
      },
      {
        "id": "09124a92-c11f-4571-b35b-ab0bce6dd081",
        "name": "T1112"
      },
      {
        "id": "f1bb7823-4f4b-4565-b472-bf0cfca467b1",
        "name": "T1486"
      },
      {
        "id": "f6ceeba2-b50c-47dc-8642-ab9842ca76d7",
        "name": "T1018"
      },
      {
        "id": "0c836307-129e-4ff7-a532-180c633cacba",
        "name": "T1027"
      },
      {
        "id": "6c8f8a40-2746-4a37-86bd-81e82afa6e62",
        "name": "T1190"
      },
      {
        "id": "19ce62bb-3faf-4d09-90b1-d82fce1ba8b0",
        "name": "T1136"
      },
      {
        "id": "e8422fc8-8365-4a6a-a556-d6ec16cb4e5d",
        "name": "T1574.002"
      },
      {
        "id": "fc699aef-8931-4a79-8f79-9651be9abd50",
        "name": "T1021"
      },
      {
        "id": "7364ca96-72bf-4b7f-afef-ce2583b1ed58",
        "name": "T1562.001"
      },
      {
        "id": "36d26fbc-439e-460e-bb28-0935ad0c1b8a",
        "name": "T1090.001"
      },
      {
        "id": "1eef7f88-3992-4add-899e-a7cc9fcdd5b3",
        "name": "T1569.002"
      },
      {
        "id": "232fbdfa-94c6-443d-b575-373e75b4f4c2",
        "name": "T1567"
      }
    ],
    "malware": [
      {
        "id": "5acd6de8-b5ef-4699-83df-1951dd74e1e2",
        "name": "DragonForce",
        "slug": "dragonforce"
      },
      {
        "id": "fcc47207-adf7-4d6c-8cfa-069e9f1ffe0f",
        "name": "Backdoor.Turn",
        "slug": "backdoorturn"
      }
    ],
    "observables": [
      {
        "id": "2d15f510-0cb3-40d9-ad85-16fc0a190db2",
        "name": "professionalhomebasedbusiness.com"
      },
      {
        "id": "5403d987-2442-433b-b5b9-1d2733d3e3f4",
        "name": "mysimerp.net"
      },
      {
        "id": "057a5e1a-618c-4aa2-9d7b-d6a540abb935",
        "name": "projetosmecanicos.com.br"
      },
      {
        "id": "6b26b20a-0417-4c5b-bca6-f207023d0f14",
        "name": "glanz-gmbh.de"
      },
      {
        "id": "b051c4b8-0545-47f3-a14f-7f80949c1ce7",
        "name": "socialbizsolutions.com"
      },
      {
        "id": "3942c161-05a3-4599-88ac-00da7a54c303",
        "name": "turnkeyaiagents.com"
      },
      {
        "id": "7625f327-38c6-4fa7-9a56-54dc9bfb00cc",
        "name": "safefire.jo"
      },
      {
        "id": "c1887429-ff28-4f39-a4cb-16f5afed8012",
        "name": "comunidadesparentais.com.br"
      },
      {
        "id": "87c76a47-6d78-4fdd-b00a-77dbf18f9f8c",
        "name": "62.164.177.25"
      },
      {
        "id": "9d05e2a7-53d1-4b86-9b53-f624f3ef1287",
        "name": "http://192.36.27.51/TechSupV18Fix3.zip"
      },
      {
        "id": "",
        "name": "ce66b8221446c9b6d83f0ce6382f430e519601641e5daaaf1ca7a8a8806cb0b0"
      },
      {
        "id": "",
        "name": "9335f61f8ad276d94455c5b6876fea48152c3cea759f2598c8108ee461fa5759"
      },
      {
        "id": "",
        "name": "e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22"
      },
      {
        "id": "",
        "name": "aea26980059ef2ad11e99556a4edfa1f8ec769fa9f06aa573b81bedf319954b5"
      },
      {
        "id": "",
        "name": "6f9fbe29f8cc2788e2bc9d631e0eea2a8e9837076837b55838005a0e654f0a9e"
      },
      {
        "id": "",
        "name": "6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4"
      },
      {
        "id": "",
        "name": "f174c19902523dcf005fa044b6598403a5e5c0a5982398d1bc0dcc5ec1cd351b"
      },
      {
        "id": "",
        "name": "cd078957167e1af4de39aecdb981cd14156fa81d5a9c6ac51e74ae5b6199a12a"
      },
      {
        "id": "",
        "name": "65ab49119c845801f29a57e8aa177146b2ffbd289d4278109b146f933380f951"
      },
      {
        "id": "",
        "name": "82b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013b"
      },
      {
        "id": "",
        "name": "821da79d727351dd67ce5df7950e9a3de6647a3cf474bb3a093f67507fed92a6"
      },
      {
        "id": "",
        "name": "d20a3c928761fe00ac522eeb474612b5804cd9108453ea8591106d5d4428428e"
      },
      {
        "id": "",
        "name": "8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2"
      },
      {
        "id": "",
        "name": "d0da2832ae1e13a98f7ce7e33a66c1b0d9797b81f69ece134e4462ea55ac923e"
      },
      {
        "id": "",
        "name": "8a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c5531"
      },
      {
        "id": "",
        "name": "048e18416177de2ead251abdf4d89837f6807c6aba4d5b1debe49adfdecbf05c"
      }
    ],
    "others": [
      {
        "id": "",
        "name": "United States of America"
      },
      {
        "id": "",
        "name": "projetosmecanicos.com.br"
      },
      {
        "id": "",
        "name": "glanz-gmbh.de"
      },
      {
        "id": "",
        "name": "mysimerp.net"
      },
      {
        "id": "",
        "name": "professionalhomebasedbusiness.com"
      },
      {
        "id": "",
        "name": "safefire.jo"
      },
      {
        "id": "",
        "name": "socialbizsolutions.com"
      },
      {
        "id": "",
        "name": "turnkeyaiagents.com"
      },
      {
        "id": "",
        "name": "comunidadesparentais.com.br"
      }
    ]
  },
  "external_refs": [
    {
      "id": "cad82006-3b06-498a-90cd-2a3a5dc3a935",
      "standard_id": "external-reference--6a9c1e1c-1dea-5d6d-adc3-f413cef54954",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://www.security.com/threat-intelligence/dragonforce-msteams-backdoor",
      "hash": null,
      "external_id": null,
      "created": "2026-06-16T17:49:13.790Z",
      "modified": "2026-06-16T17:49:13.790Z",
      "createdById": null
    },
    {
      "id": "99891802-6f81-4ddc-83f0-212f470ec1eb",
      "standard_id": "external-reference--94269595-8c21-5ac0-af50-f719213830dc",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://otx.alienvault.com/pulse/6a316151d9ab4af59e56576d",
      "hash": null,
      "external_id": "6a316151d9ab4af59e56576d",
      "created": "2026-06-16T17:49:13.730Z",
      "modified": "2026-06-16T17:49:13.730Z",
      "createdById": null
    }
  ]
}