2026-06-17HIGHDragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)
DragonForce Backdoor.Turn intrusion
campaign · campaign:dragonforce-backdoor-turn-teams-relay-byovd
DragonForce intrusion featuring the first in-the-wild Microsoft Teams TURN-relay C2 (Backdoor.Turn) plus a four-driver BYOVD chain.
Coverage
1
first 2026-06-17 → last 2026-06-17
Latest activity
2026-06-17
DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)
Peak priority
high
1 high
Targets
technology
sectors: technology, public-sector · regions: us
Sources cited
13
4 hosts
Defender insights
What each entry about DragonForce Backdoor.Turn intrusion tells a defender to do, newest first.
Detection
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
attributed to
Story timeline
- 2026-06-17DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)
Hunting pivots
ATT&CK techniques (13 across 10 tactics)
13 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionHijack Execution Flow · Hijack Execution Flow: DLL
- PersistenceCreate Account · Create Account: Local Account
- Privilege EscalationExploitation for Privilege Escalation
- StealthHijack Execution Flow · Hijack Execution Flow: DLL
- Defense ImpairmentDisable or Modify Tools
- Credential AccessCredentials from Password Stores · Credentials from Password Stores: Credentials from Web Browsers
- DiscoveryRemote System Discovery · Network Service Discovery
- Lateral MovementRemote Services
- Command and ControlProxy
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Execution TA0002
T1574Hijack Execution Flow×1
Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Persistence TA0003
T1136Create Account×1
Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1136.001Create Account: Local Account×1
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Stealth TA0005
T1574Hijack Execution Flow×1
Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Credential Access TA0006
T1555Credentials from Password Stores×1
Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1555.003Credentials from Password Stores: Credentials from Web Browsers×1
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Discovery TA0007
T1018Remote System Discovery×1
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <code>net view</code> using Net, or, on ESXi servers, `esxcli network diag ping`.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
T1046Network Service Discovery×1
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Lateral Movement TA0008
T1021Remote Services×1
Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Command and Control TA0011
T1090Proxy×1
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Evidence: 2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch · ATT&CK page ↗
Entries about DragonForce Backdoor.Turn intrusion (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- attack.mitre.org10 (77%)
- bleepingcomputer.com1 (8%)
- helpnetsecurity.com1 (8%)
- security.com1 (8%)
All cited sources (13)
- attack.mitre.org`T1018`https://attack.mitre.org/techniques/T1018/
- attack.mitre.org`T1021`https://attack.mitre.org/techniques/T1021/
- attack.mitre.org`T1046`https://attack.mitre.org/techniques/T1046/
- attack.mitre.org`T1068` Exploitation for Privilege Escalationhttps://attack.mitre.org/techniques/T1068/
- attack.mitre.org`T1090` Proxyhttps://attack.mitre.org/techniques/T1090/
- attack.mitre.org`T1136.001`https://attack.mitre.org/techniques/T1136/001/
- attack.mitre.org`T1190` Exploit Public-Facing Applicationhttps://attack.mitre.org/techniques/T1190/
- attack.mitre.org`T1555.003`https://attack.mitre.org/techniques/T1555/003/
- attack.mitre.org`T1562.001` Impair Defenseshttps://attack.mitre.org/techniques/T1562/001/
- attack.mitre.org`T1574.002`https://attack.mitre.org/techniques/T1574/002/
- bleepingcomputer.comBleepingComputer, 2026-06-16https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/
- helpnetsecurity.comHelp Net Security, 2026-06-16https://www.helpnetsecurity.com/2026/06/16/dragonforce-microsoft-teams-malware-backdoor-turn/
- security.comSymantec / Broadcom, 2026-06-16https://www.security.com/threat-intelligence/dragonforce-msteams-backdoor