Back to Blog
CVE-2023-52271, CVE-2025-61155, CVE-2025-1055: Microsoft Teams TURN Relay — Stealthy C2 Evasion Attack (June 2026)
vulnerabilities

CVE-2023-52271, CVE-2025-61155, CVE-2025-1055: Microsoft Teams TURN Relay — Stealthy C2 Evasion Attack (June 2026)

breachwire TeamJun 19, 20262 min read

CVE-2023-52271, CVE-2025-61155, CVE-2025-1055 — Microsoft Teams TURN Relay

These high-severity CVEs enable attackers to covertly route command-and-control (C2) traffic through Microsoft Teams TURN relay infrastructure. The vulnerabilities are actively exploited in the wild, allowing persistent network access and evasion of traditional security controls. No CVSS score is published, but the impact is confirmed as critical.

Attack Vector

DragonForce ransomware operators deployed a custom Go-based remote access trojan (Backdoor.Turn) on a major U.S. services firm’s network. The malware abuses Microsoft Teams’ TURN relay servers to encapsulate C2 communications, blending malicious traffic with legitimate collaboration flows. Attackers maintained access for up to two months, leveraging BYOVD (Bring Your Own Vulnerable Driver) techniques by deploying a vulnerable Huawei driver to disable endpoint security. This multi-vector approach enabled reconnaissance, credential theft, and lateral movement while evading detection by network and host-based controls.

Who Is at Risk

Organizations using Microsoft Teams, especially those with exposed or misconfigured TURN relay endpoints, are at elevated risk. The confirmed victim is a major U.S. services firm, but any enterprise leveraging Teams for internal or external communications is potentially vulnerable. Security software relying solely on signature or heuristic detection is likely to be bypassed if vulnerable drivers are present.

Patch & Mitigate

  • Patch: Apply Microsoft security updates addressing CVE-2023-52271, CVE-2025-61155, and CVE-2025-1055 as soon as available. Monitor Microsoft advisories for hotfix release dates.
  • Workaround: Restrict outbound TURN traffic to trusted domains. Audit and harden Teams relay configurations. Block known vulnerable Huawei driver hashes and prevent unsigned driver loading.
  • Detect: Monitor for anomalous Teams relay traffic, unexpected Go-based binaries, and signs of BYOVD activity. Review endpoint logs for driver installation events and lateral movement indicators.

MITRE ATT&CK

  • TA0005 — Defense Evasion: Attackers used BYOVD to disable security controls and evade detection.
  • TA0011 — Command and Control: C2 traffic was tunneled through Microsoft Teams TURN relays to blend with legitimate traffic.
  • TA0008 — Lateral Movement: The attackers leveraged stolen credentials and persistence to move laterally across the network.

Source: https://thehackernews.com/2026/06/dragonforce-hackers-abuse-microsoft.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: