Back to all lessons
Awareness Lessons
4 months ago

DragonForce Hides C2 Traffic Inside Microsoft Teams Relay Infrastructure

The DragonForce ransomware gang exploited the TURN protocol within Microsoft Teams' relay infrastructure to disguise malicious command-and-control traffic as legitimate business communications, effectively bypassing traditional network-based detection tools. This tactic is significant because it weaponizes trusted, widely-deployed SaaS platforms, making it extremely difficult to distinguish malicious traffic from normal enterprise activity. Additionally, the use of vulnerable drivers for privilege escalation compounded the threat by undermining endpoint security controls. This highlights the growing trend of attackers 'living off trusted services' to evade defenses. Organizations that rely solely on perimeter-based or signature-based detection are particularly exposed to this class of attack.

Tactical Insight

Immediate actions

  • Deploy deep packet inspection and behavioral analytics tools capable of detecting anomalous TURN/STUN protocol usage even within trusted application traffic.
  • Audit and restrict which internal systems are permitted to establish outbound connections through Microsoft Teams relay endpoints.
  • Scan all endpoints for known vulnerable drivers (BYOVD) using tools like Microsoft's vulnerable driver blocklist or DriverQuery audits.

Long-term improvements

  • Implement Zero Trust Network Access (ZTNA) to enforce least-privilege connectivity and reduce implicit trust granted to SaaS relay services.
  • Establish microsegmentation policies that limit lateral movement even when C2 traffic successfully masquerades as legitimate application traffic.
  • Maintain a continuously updated allowlist of approved drivers and enforce kernel-level driver signing policies via WDAC or similar controls.

Detection measures

  • Integrate SIEM rules to flag unusual volumes or timing patterns of Teams relay traffic originating from non-standard endpoints or service accounts.
  • Enable endpoint detection and response (EDR) telemetry to identify privilege escalation events associated with vulnerable driver exploitation.
  • Correlate network flow data with identity and access logs to detect mismatches between expected Teams usage patterns and actual relay communications.