Backdoor.Turn is a custom Go-based remote access trojan associated with DragonForce ransomware intrusions. It is notable for abusing Microsoft Teams TURN relay infrastructure to conceal command-and-control traffic inside trusted enterprise collaboration traffic, causing network monitoring to primarily observe outbound connections to legitimate Microsoft Teams services rather than obviously malicious destinations. The malware obtains an anonymous Teams visitor token from Microsoft’s Skype-backed identity services, uses a legitimate Microsoft TURN relay to establish connectivity, and then runs a QUIC-based session to attacker-controlled infrastructure. This tradecraft has been assessed as the first known in-the-wild malware use of Microsoft Teams TURN relays for covert command and control, reflecting a practical implementation of the Ghost Calls-style tunneling concept.
Backdoor.Turn has been observed in a DragonForce intrusion against a major U.S. services firm, where attackers reportedly maintained access for roughly one to two months before ransomware deployment. The broader intrusion involved likely exploitation of an exposed SQL or Microsoft SQL Server vulnerability, though brokered access has also been considered possible. Operators used DLL sideloading, account creation, firewall and security-setting changes, and multi-vector BYOVD-based defense evasion to preserve access and suppress security tooling. Backdoor.Turn itself supports remote command execution, process creation, internal network scanning, LDAP and Active Directory reconnaissance, credential-based lateral movement, browser credential theft, and collection of certificate-related information. It has also been observed injected into a legitimate process after ransomware deployment, suggesting use for persistence, post-encryption access retention, or resale of access.
The malware targets Windows environments and has been linked to highly sophisticated ransomware tradecraft emphasizing stealth, persistence, reconnaissance, credential theft, lateral movement, and post-compromise control in enterprise networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
6월 공개된 Microsoft Teams 릴레이(TURN) 인프라를 악용해 C2(명령·제어) 트래픽을 은닉하는 'Backdoor.Turn' 사례입니다.
Операторы вымогательской группировки DragonForce начали использовать необычную тактику для маскировки своей активности... в одной из недавних атак хакеры использовали кастомный бэкдор Backdoor.Turn, который маскирует обмен данными с управляющим сервером под обычный трафик Microsoft Teams.
Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft, and the routine use of EDR-killer tooling and Bring Your Own Vulnerable Driver techniques ahead of impact.
The cybercriminals used a Go-based Remote Access Trojan (RAT) to abuse Microsoft Teams' TURN relay servers and mask command-and-control traffic.
It manually initiated WebRTC sessions using hijacked TURN credentials, tricking Microsoft's infrastructure into acting as a blind, trusted proxy for arbitrary C2 traffic.
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft, and the routine use of EDR-killer tooling and Bring Your Own Vulnerable Driver techniques ahead of impact.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom Go-based remote access trojan used by a DragonForce affiliate for covert command-and-control by tunneling traffic through Microsoft Teams TURN relay infrastructure.
Microsoft Teams TURN 인프라를 악용해 C2 트래픽을 정상 서비스 내부에 은닉함으로써 탐지를 회피하는 백도어 사례로 설명된다.
A custom Go-based backdoor/RAT used to tunnel command-and-control traffic through Microsoft Teams/Skype TURN relay infrastructure by retrieving a visitor token, setting up a legitimate TURN relay, and establishing outbound QUIC/WebRTC-based encrypted C2 sessions for covert persistence.
Custom Go-based backdoor used by DragonForce that tunnels C2 communications through Microsoft Teams TURN infrastructure and QUIC sessions to disguise malicious traffic as legitimate Teams traffic. It supports command execution, process launching, network scanning, LDAP and Active Directory discovery, TLS certificate collection, and browser credential theft, likely to enable persistence and future re-entry after ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.