
Unnamed US Services Firm Ransomware: DragonForce Abuses Microsoft Teams Relay (June 2024)
Unnamed US Services Firm: What Happened
In June 2024, an unnamed US services firm experienced a critical ransomware incident attributed to the DragonForce group. The attackers deployed a newly identified Go-based backdoor, Backdoor.Turn, which exploited Microsoft Teams relay servers to establish covert command-and-control (C2) channels. This allowed the threat actors to maintain persistent access, evade detection, and coordinate the attack phases. The compromise resulted in the termination of security processes, data encryption, credential theft, and exfiltration of sensitive information, all while leveraging legitimate Microsoft Teams traffic to mask malicious activity.
Attack Vector & Technical Detail
Initial access was likely achieved via exploitation of a vulnerable SQL or MSSQL server, granting the attackers a foothold within the target network. The DragonForce group then deployed Backdoor.Turn, a Go-based implant engineered to communicate through Microsoft Teams relay servers, effectively blending C2 traffic with normal enterprise collaboration flows. This abuse of Teams infrastructure enabled lateral movement and persistence while evading conventional network monitoring. The attackers executed kernel-level operations, terminated security controls, and staged ransomware deployment. MITRE ATT&CK tactics observed include Initial Access (TA0001), Persistence (TA0003), Defense Evasion (TA0005), Credential Access (TA0006), Discovery (TA0007), Command and Control (TA0011), and Exfiltration (TA0010).
Confirmed Impact
The incident led to full network compromise within the affected US services firm, with attackers achieving kernel-level access and disabling security mechanisms. Ransomware payloads were deployed, resulting in widespread data encryption and operational disruption. Additionally, credential theft and data exfiltration were confirmed, with persistent backdoor access maintained through Teams relay channels. The use of legitimate Microsoft Teams infrastructure for C2 communications significantly complicated detection and response efforts. While the organization remains unnamed, the attack underscores the risk to North American service providers and the potential for regulatory scrutiny due to data loss and exposure.
What This Means for Your Organization
This incident demonstrates the evolving tactics of ransomware groups in leveraging trusted cloud collaboration platforms for covert operations. Organizations relying on Microsoft Teams should be aware that its relay servers can be abused for malicious C2, bypassing traditional perimeter defenses. Security teams must monitor for anomalous Teams traffic patterns, especially those indicative of non-standard communication or persistent connections. Proactive threat hunting and segmentation of collaboration services are essential to reduce the attack surface and detect lateral movement early.
Detection & Response
- Immediate: Review and analyze Microsoft Teams network traffic for unusual relay server communications and persistent outbound connections.
- Hunt: Search for deployment or execution of Go-based binaries (e.g., Backdoor.Turn) and monitor for anomalous process termination of security tools.
- Patch: N/A (no specific CVE identified in this incident; review and harden SQL/MSSQL server configurations and patch known vulnerabilities).
Source: https://www.securityweek.com/microsoft-teams-relay-servers-abused-in-dragonforce-ransomware-attack/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

