Backdoor.Turn is a custom Go-based remote access trojan associated with DragonForce ransomware intrusions. It is notable for concealing command-and-control communications inside Microsoft Teams TURN relay infrastructure, causing malicious traffic to resemble legitimate enterprise collaboration traffic. The malware obtains an anonymous Teams visitor token from Microsoft’s Skype-backed identity services, uses a legitimate Microsoft TURN relay to establish connectivity, and then initiates a QUIC-based session to attacker-controlled command-and-control infrastructure. This tradecraft has been assessed as the first known in-the-wild malware use of a Ghost Calls-style covert tunneling approach against Microsoft Teams relay services.
Backdoor.Turn has been observed in an intrusion against a major U.S. services firm in which DragonForce operators likely gained initial access through exploitation of an exposed SQL or Microsoft SQL Server vulnerability, although brokered access from an initial access broker has also been considered possible. During the intrusion, the operators used DLL sideloading, process injection, persistence measures, account creation, firewall and system configuration changes, and bring-your-own-vulnerable-driver techniques to disable security tooling and maintain access. The malware has been reported injected into a legitimate Windows process after ransomware deployment, suggesting use for continued covert access, possible re-entry, or resale of access after encryption.
Its supported functionality includes remote command execution, process creation, internal network scanning, LDAP and Active Directory enumeration, collection of TLS certificate information, credential-based lateral movement, and theft of browser-stored credentials. The malware therefore serves both post-compromise operational needs and long-term access objectives. Backdoor.Turn reflects a broader increase in sophistication among DragonForce-linked tooling and demonstrates how trusted cloud and collaboration infrastructure can be repurposed for stealthy command-and-control in ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
6월 공개된 Microsoft Teams 릴레이(TURN) 인프라를 악용해 C2(명령·제어) 트래픽을 은닉하는 'Backdoor.Turn' 사례입니다.
Операторы вымогательской группировки DragonForce начали использовать необычную тактику для маскировки своей активности... в одной из недавних атак хакеры использовали кастомный бэкдор Backdoor.Turn, который маскирует обмен данными с управляющим сервером под обычный трафик Microsoft Teams.
Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Функциональность нового бэкдора включает ... сканирование сети
Microsoft Teams 릴레이(TURN) 인프라를 악용해 C2(명령·제어) 트래픽을 은닉하는 'Backdoor.Turn' 사례
Tracked as Backdoor.Turn, the newly identified malware is written in Go and hides its C&C server communication as legitimate Microsoft Teams traffic in a sophisticated manner. “Backdoor.Turn obtains an anonymous Teams visitor token from Microsoft’s Skype-backed identity services, uses a legitimate Microsoft TURN relay to set up the connection, and then runs a QUIC session to the attacker’s real [C&C] server,”
It manually initiated WebRTC sessions using hijacked TURN credentials, tricking Microsoft's infrastructure into acting as a blind, trusted proxy for arbitrary C2 traffic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Microsoft Teams TURN 인프라를 악용해 C2 트래픽을 정상 서비스 내부에 은닉함으로써 탐지를 회피하는 백도어 사례로 설명된다.
A custom Go-based backdoor/RAT used to tunnel command-and-control traffic through Microsoft Teams/Skype TURN relay infrastructure by retrieving a visitor token, setting up a legitimate TURN relay, and establishing outbound QUIC/WebRTC-based encrypted C2 sessions for covert persistence.
Custom Go-based backdoor used by DragonForce that tunnels C2 communications through Microsoft Teams TURN infrastructure and QUIC sessions to disguise malicious traffic as legitimate Teams traffic. It supports command execution, process launching, network scanning, LDAP and Active Directory discovery, TLS certificate collection, and browser credential theft, likely to enable persistence and future re-entry after ransomware deployment.
A custom Go-based remote access trojan used to hide C2 traffic via Microsoft Teams TURN relay infrastructure. It obtains anonymous Teams visitor tokens, uses legitimate Microsoft TURN relays for connection setup, and then establishes a QUIC session to the real C2 server. It supports command execution, process creation, network scanning, LDAP and Active Directory search, credential-based lateral movement, and browser credential theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.