DragonForce ransomware backdoor weaponises legit Microsoft Teams servers

Ransomware is not dead, nor is it pining for the fjords. As the latest DragonForce attacks have confirmed, the enterprise threat is alive and well. Oh, and it’s now using Microsoft Teams relay servers for command and control of a dangerous backdoor, according to the Symantec and Carbon Black threat hunter team.

The backdoor takes the form of a Go-based remote access trojan. It’s the first known malware to manipulate Microsoft Teams’ TURN relay servers in a way that can mask its command-and-control traffic.

“To network defenders,” the Symantec and Carbon Black report said, “the only traffic they could see was outbound connections to legitimate Microsoft Teams servers.”

As a result, the custom malware that is being tracked as Backdoor.Turn can remain hidden on the victim network for up to two months.

All of this is important for many reasons. Not only are these attacks a first in terms of abusing the Teams infrastructure like this, it’s also a change in tactic for ransomware attackers: DragonForce is ransomware-as-a-service criminal operation, so it’s unusual to use such custom tooling.

Indeed, the report stated that “it is particularly unusual to see them using a custom tool as sophisticated as Backdoor.Turn”.

The as-yet-unnamed victim, only known to be a US services firm, is thought to have been initially compromised through an as-yet-unknown vulnerability in an SQL or MSSQL server.

“Microsoft Teams relay servers help Teams traffic connect when users cannot reach each other directly, often through TURN-based relay infrastructure,” said Craig Birch, Principal Technologist at Cayosoft. The traffic relayed by TURN is expected, encrypted and, crucially, most commonly allowed.

“DragonForce was able to make command-and-control activity look like normal Teams communication,” Birch concluded.

How the attack works (image: Symantec)

Evolution of ransomware tradecraft

“This is a solid example of how ransomware tradecraft is continuing to evolve,” warned Robert Coles, Senior Manager of Threat Intelligence Security at Black Duck. “Frankly, it’s more about the abuse of trusted infrastructure than just a new piece of malware.”

The takeaway being that it reinforces a broader trend, with DragonForce investing in custom tooling, “Bring Your Own Vulnerable Driver” methods for defence evasion, and now leveraging trusted cloud services to stay persistent and operate under the radar. 

As Coles said, “that’s not typical ‘smash-and-grab’ ransomware anymore; it’s much closer to what we historically associated with more advanced threat actors”.

I will leave the last words with Shane Barney, Chief Information Security Officer at Keeper Security, who told me that the practical response is to apply zero-trust principles consistently, not selectively.

“Every session should be validated, every access path monitored, and anomalous behaviour flagged regardless of whether the traffic originates from a trusted tool,” Barney said.

“The organisations with the strongest position here are those that have already extended that discipline beyond traditional IT infrastructure to include the collaboration layer.”

More by Davey Winder

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.