Microsoft Teams users beware: Relays are being hit by ransomware hackers seeking to hide malicious traffic


  • Symantec Confirms DragonForce Ransomware Operators Used Microsoft Teams TURN Relays for Covert C2 Traffic
  • Custom Go-based RAT “Backdoor.Turn” hid malicious activity as normal Teams communications
  • First use in the wilderness of the “ghost calls” technique; the campaign shows very sophisticated craftsmanship with Scattered Spider links

Experts have warned that cybercriminals are using Microsoft Teams relays as command and control (C2) infrastructure, mixing malicious traffic with innocuous corporate communications.

In Microsoft Teams, a relay is a server that helps route audio and video traffic when a direct connection between participants is not possible (for example, if they are on a corporate network or behind a firewall).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top