
Unnamed Major U.S. Services Company Ransomware: DragonForce Abuses Microsoft Teams TURN Relays (June 2024)
Unnamed Major U.S. Services Company: What Happened
In June 2024, a major U.S. services company was targeted in a critical ransomware operation attributed to the DragonForce ransomware gang. The attackers deployed a custom backdoor, Backdoor.Turn, specifically engineered to exploit Microsoft Teams TURN relay infrastructure, allowing them to conceal their command-and-control (C2) communications. The breach resulted in the exfiltration of sensitive data and the encryption of core systems, severely impacting business operations. DragonForce’s use of legitimate Microsoft Teams infrastructure for malicious traffic significantly complicated detection and response efforts.
Attack Vector & Technical Detail
Initial access was achieved through exploitation of an unknown vulnerability in an SQL or MSSQL server, with evidence suggesting the use of CVE-2023-52271, CVE-2025-61155, and CVE-2025-1055 during lateral movement and privilege escalation. The attackers leveraged multiple Bring Your Own Vulnerable Driver (BYOVD) techniques, including the deployment of drivers such as Huawei HWAuidoOs2Ec.sys, Topaz Antifraud wsftprm.sys, Tower of Fantasy GameDriverx64.sys, and K7 Security K7RKScan.sys. Additionally, the ABYSSWORKER malicious driver masqueraded as a Palo Alto driver, and DbgView64.exe was used for DLL sideloading. The MITRE ATT&CK tactics observed include Initial Access (TA0001), Defense Evasion (TA0005), Discovery (TA0007), Command and Control (TA0011), Impact (TA0040), and Exfiltration (TA0043).
Confirmed Impact
The incident led to both data exfiltration and widespread system encryption across the victim’s North American operations. The attackers’ use of Microsoft Teams TURN relays allowed them to evade network-based detection and maintain persistent access. The abuse of vulnerable drivers for kernel-level access enabled the attackers to bypass endpoint security controls, resulting in a stealthy and prolonged dwell time. Given the scale and sophistication of the attack, regulatory notification and incident reporting obligations are likely triggered for the affected organization.
What This Means for Your Organization
This incident demonstrates the increasing trend of ransomware groups abusing legitimate cloud collaboration infrastructure, such as Microsoft Teams TURN relays, to mask malicious activity. Organizations should prioritize monitoring for anomalous traffic over sanctioned platforms and rigorously control the use of third-party and legacy drivers. Proactive vulnerability management, especially for SQL/MSSQL servers, and the implementation of robust detection rules for BYOVD techniques are critical to reducing exposure to similar threats.
Detection & Response
- Immediate: Audit and restrict outbound traffic to Microsoft Teams TURN relay endpoints for anomalous patterns.
- Hunt: Search for presence of Backdoor.Turn RAT, ABYSSWORKER driver, and evidence of DbgView64.exe DLL sideloading.
- Patch: Apply updates addressing CVE-2023-52271, CVE-2025-61155, and CVE-2025-1055 across SQL/MSSQL infrastructure.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

