Back to all lessons
Awareness Lessons
4 months ago

DragonForce Abuses Microsoft Teams Relay Servers to Hide Ransomware C2 Traffic

The DragonForce ransomware group exploited Microsoft Teams TURN relay servers to disguise malicious command-and-control traffic as legitimate corporate communications, making detection extremely difficult. Attackers gained initial access using stolen credentials and leveraged DLL sideloading and Bring Your Own Vulnerable Driver (BYOVD) techniques to achieve deep system persistence before deploying ransomware. This attack highlights the danger of blindly trusting traffic from well-known SaaS platforms without inspecting it for anomalies. Organizations that fail to scrutinize outbound traffic to trusted services create a hidden channel that attackers can exploit with impunity. The incident underscores that perimeter-based trust of legitimate application traffic is no longer sufficient in a modern threat landscape.

Tactical Insight

Immediate actions

  • Audit and restrict outbound connections to Microsoft Teams relay servers by enforcing allowlists limited to known corporate endpoints.
  • Rotate all privileged credentials immediately and enforce phishing-resistant MFA across all accounts to eliminate stolen credential reuse.
  • Deploy EDR solutions capable of detecting DLL sideloading and BYOVD driver abuse patterns on all endpoints.

Long-term improvements

  • Implement zero-trust network architecture so that even traffic to trusted SaaS platforms is inspected and contextualized before being allowed.
  • Enforce strict driver signing policies and use Windows Defender Credential Guard and HVCI to prevent BYOVD techniques.
  • Segment internal networks so that a compromised endpoint cannot freely communicate outbound through collaboration platforms without explicit policy approval.

Detection measures

  • Enable deep packet inspection and behavioral analytics to flag unusual volumes or patterns of traffic routed through Microsoft Teams TURN/STUN relay infrastructure.
  • Monitor for anomalous process behavior such as unexpected parent-child process relationships and unsigned DLL loads indicative of sideloading.
  • Establish a baseline of normal Teams traffic per user and alert on deviations that may indicate covert C2 channel usage.