Microsoft Teams users beware – relays hit by ransomware hackers looking to hide malicious traffic


  • Symantec confirms DragonForce ransomware operators used Microsoft Teams TURN relays to covert C2 traffic
  • Custom Go-based RAT “Backdoor.Turn” masked malicious activity as normal Teams communication
  • The first in-wild use of the “Ghost Calls” technique; campaign shows very sophisticated craftsmanship with scattered spider links

Experts have warned that cybercriminals are using Microsoft Teams relays as command-and-control (C2) infrastructure, mixing malicious traffic with benign corporate communications.

In Microsoft Teams, a relay is a server that helps transport audio and video traffic when a direct connection between participants is not possible (for example, they are on a corporate network or behind a firewall).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top