Microsoft Teams users beware: Relays are targeted by ransomware hackers looking to hide malicious traffic



  • Symantec confirms DragonForce ransomware operators used Microsoft Teams TURN relays for covert C2 traffic
  • Go-based custom RAT “Backdoor.Turn” masked malicious activity as normal Teams communications
  • First use in the wild of the “Ghost Calls” technique; The campaign showcases highly sophisticated crafts with scattered spider links.

Experts have warned that cybercriminals are using Microsoft Teams relays as command and control (C2) infrastructure, combining malicious traffic with benign corporate communications.

In Microsoft Teams, a repeater is a server that helps transport audio and video traffic when a direct connection between participants is not possible (for example, they are on a corporate network or behind a firewall).

Leave a Comment

Your email address will not be published. Required fields are marked *