Backdoor.Turn is a custom Go-based remote access trojan used by DragonForce ransomware operators during an intrusion against a major U.S. services organization. It conceals command-and-control communications through Microsoft Teams TURN relay infrastructure. The implant acquires an anonymous Teams visitor token from Microsoft’s Skype-backed identity services, establishes relay-assisted connectivity through legitimate Teams infrastructure, and uses QUIC to communicate with attacker-controlled command-and-control infrastructure. This design causes network telemetry to resemble ordinary outbound Microsoft Teams traffic. Backdoor.Turn was deployed following ransomware activity, apparently to retain covert access for follow-on operations. It supports remote command execution and process creation, network scanning, LDAP and Active Directory discovery, TLS certificate collection, credential-based lateral movement, and browser credential theft. DragonForce operators also used DLL sideloading, vulnerable-driver abuse, security-control modification, account creation, and firewall changes during the associated intrusion; these surrounding techniques supported persistence and defense evasion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
The drivers involved included Huawei’s HWAuidoOs2Ec.sys, Topaz Antifraud’s wsftprm.sys (CVE-2023-52271), Tower of Fantasy’s GameDriverx64.sys (CVE-2025-61155), and K7 Security’s K7RKScan.sys (CVE-2025-1055).
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
An attack using a custom “Backdoor.Turn” implant abused Microsoft Teams infrastructure to hide its command-and-control traffic.
Операторы вымогательской группировки DragonForce начали использовать необычную тактику для маскировки своей активности... в одной из недавних атак хакеры использовали кастомный бэкдор Backdoor.Turn, который маскирует обмен данными с управляющим сервером под обычный трафик Microsoft Teams.
Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling.
The initial compromise occurred via social engineering on Microsoft Teams. An external actor impersonating IT support convinced a user to run a PowerShell command that downloaded an archive containing a staged Python 3.12.9 embeddable runtime and a 39 MB compiled payload.
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft, and the routine use of EDR-killer tooling and Bring Your Own Vulnerable Driver techniques ahead of impact.
The cybercriminals used a Go-based Remote Access Trojan (RAT) to abuse Microsoft Teams' TURN relay servers and mask command-and-control traffic.
It manually initiated WebRTC sessions using hijacked TURN credentials, tricking Microsoft's infrastructure into acting as a blind, trusted proxy for arbitrary C2 traffic.
The reverse SOCKS5 tunnel is the interactive access channel. It runs over either a direct TLS/WebSocket connection to the attacker’s server or through the Teams TURN WebRTC relay.
ou via les relais TURN de Microsoft Teams ... en utilisant des WebRTC DataChannels
Ransomware operators continued to rely on a consistent set of Tactics, Techniques, and Procedures (TTPs), including exploitation of internet-facing edge devices and remote management tooling, abuse of valid accounts, credential theft, and the routine use of EDR-killer tooling and Bring Your Own Vulnerable Driver techniques ahead of impact.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom implant associated with DragonForce activity that tunnels command-and-control traffic through legitimate Microsoft Teams infrastructure, allowing prolonged dwell time while blending with normal business communications.
Backdoor referenced for sharing Teams TURN relay abuse with TWINLOOT, but otherwise described as different in language, access vector, and broader tradecraft.
A backdoor malware referenced as an earlier example of abusing Microsoft Teams TURN relay infrastructure to disguise C2 traffic.
A Go-based remote access trojan used to conceal C2 traffic inside Microsoft Teams relay infrastructure, using a QUIC session through the relay.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.