NEWS “Nothing suspicious, just Teams.” Hackers hid the control of the virus for regular working correspondence

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,247
The first case of using the Microsoft Teams infrastructure to hide the control of malware has been discovered.
1781797515354.png
Hackers have found a way to hide communication with the infected network where it is least expected: for conventional connections to Microsoft Teams. Symantec described the DragonForce attack on a major American service company, where the new module Backdoor.Turn helped attackers hide how they controlled the malware, behind Microsoft’s legitimate infrastructure.

According to Symantec, the attackers were online from one to two months. For hidden communication, they used a new remote module Backdoor.Turn, written on Go. The malware received an anonymous guest token Microsoft Teams through Skype identification services, connected to Microsoft TRENN’s legal relay servers, and then installed a QUIC session with a real hacker management server.

Symantec experts believe that this is the first known case when the malware in a real attack used the TURN infrastructure in Microsoft Teams in this way. For defenders, the picture looked like ordinary outgoing traffic to Microsoft, although through such a scheme the attackers kept a hidden control channel.

Initial access, according to the preliminary version, was obtained through a vulnerability in the SQL or MSSQL server, but the specific gap is still unknown. It is not excluded that access was bought from intermediaries. The activity began in December 2025. After infiltrating the network, the hackers uploaded the ZIP archive with a legitimate executable VirtualBox or DbgView and the malicious library vboxt.dll. Such a reception allowed to force a trusted program to run someone else's code.

The attackers were fixed in the system, changed the settings of remote access, added users and groups, and also adjusted the rules of the firewall so that communication with their servers is not blocked. To bypass the defense, the technique “bring your vulnerable driver” was used. Hackers used signed but vulnerable drivers to gain access at the core level and complete the processes of security programs.

Symantec paid special attention to the driver of Huawei HWAuidoOs2Ec.sys. Before this attack, it was not known that it was used in real hacks, although later, in March 2026, Huntress specialists described his vulnerable status. The campaign also found vulnerable drivers Topaz Antifraud, Tower of Fantasy and K7 Security Anti-Malware, as well as the malware driver Abyss Worker, disguised as a legitimate component Palo Alto.

After conducting reconnaissance and disabling the defense mechanisms, the group deployed DragonForce, stole data and encrypted the victim’s systems. Backdoor.Turn, judging by the sequence of the attack, was installed after the ransomware was launched. Such a step may indicate a desire to save access in order to re-enter the system or sell it to other intruders.

Backdoor.Turn is able to execute commands, run processes, scan the network, collect information about TLS certificates and web page titles, search for data in LDAP and Active Directory, move around the network with stolen credentials and pull passwords out of browsers on infected devices.

Symantec connects DragonForce with the Hackledorb band. According to the company, the project, active at least since June 2023, moved from the usual model “encryptor as a service” to a more organized structure. Backdoor.Turn and several ways to bypass protection through drivers indicate that DragonForce operators have significantly increased technical capabilities after 2025.
 
5,610Threads
75,229Messages
5,815Members
Suspect69Latest member
Top Bottom