Backdoor 1 – TURN | Image: Lab52
At a Glance
| Malware family | Two backdoors: a Go-based in-memory implant and a persistent TURN/MQTT backdoor |
| Threat actor | DragonForce ransomware operation (attributed by Lab52) |
| Targets | Not disclosed by Lab52; Symantec earlier reported a US services firm |
| Delivery vector | Post-compromise; initial access not described |
| Key capabilities | C2 through Teams TURN relays, MQTT fallback, DLL sideloading, DPAPI-locked payload, memory encryption while idle |
| Sources | Lab52; Symantec |
TL;DR
DragonForce hides backdoor traffic inside Microsoft Teams relay servers, so it looks like normal Teams calls. A newer backdoor adds MQTT as a backup channel if that route fails. It also locks its payload to each infected PC and encrypts itself while inactive.
Delivery
Lab52 does not explain how the attackers first get in. Instead, it describes two backdoors used after the break-in. The first appears in an early deployment phase. The second is meant to “remain resident on disk, albeit protected.”
Symantec first exposed the Teams relay trick in June 2026. In that case, attackers sat inside a US services company for one to two months. Symantec said: “To our knowledge this is the first time TURN relay infrastructure has been abused this way in the wild.”
Infection Chain
Backdoor 1: Straight Into Memory
The first backdoor is written in Go and runs only in memory. It decrypts its server address at runtime, so the address never sits on disk in plain text. It also keeps a private key for SSH-based communication.
Backdoor 2: Sideloaded and Locked to One PC
The second backdoor runs through a scheduled task left by an earlier stage. It abuses a legitimate Java executable that loads a malicious DLL from the same folder. That DLL then loads the next stage from a text file.
The text file is encrypted with Windows DPAPI. As a result, it only decrypts on the machine where it was created. Copying it to a lab system will not work. Moreover, the loader DLL has a different hash on every system, which defeats simple hash blocklists.
Command-and-Control and Data Exfiltration
Hiding in Teams Relays
TURN servers help video and voice calls cross firewalls. Microsoft Teams runs its own TURN servers. DragonForce routes its traffic through them, so network tools see what looks like Teams activity. Symantec found that the earlier backdoor grabbed an anonymous Teams visitor token to reach those relays.
Over this channel, the backdoor checks for tasks, downloads them in chunks, and checks each chunk’s MD5 hash. Then it decrypts the payload and runs it in a new thread. It can also upload data in small blocks, though Lab52 saw this used only during the first handshake.
MQTT as a Backup Line
If the TURN route fails, the backdoor turns to an MQTT broker. It registers a session and then polls a task topic tied to the system’s ID. Tasks arrive as small XOR-encrypted JSON messages. Payloads follow in numbered chunks on separate topics.
Each task fills in a code template. Depending on the command, it can fetch a URL, run a PowerShell line, run a payload as-is, or connect to a remote host and port.
Encrypting Itself While Asleep
When communication fails, the backdoor sleeps for five minutes. Before it does, it encrypts its own memory region. Lab52 says this aims “to evade detection by security tools while it is inactive.”
Attribution
Lab52 ties both backdoors to DragonForce. It links the first to Symantec’s earlier findings and connects a related loader file to past DragonForce reports. This is a vendor attribution. No law enforcement action against these operators has been announced.
DragonForce emerged around 2023 as a ransomware-as-a-service group. Lab52 says it has since grown into what some call a “ransomware cartel.” It now offers infrastructure and tools to affiliates, not just encryption.
Defense and Detection Guidance
The DragonForce backdoor blends into trusted traffic, so defenders need behavior-based checks:
- Alert on non-Teams processes that connect to Microsoft Teams TURN relays.
- Flag MQTT traffic from workstations and servers that have no IoT role.
- Watch for legitimate Java binaries loading DLLs from unusual folders.
- Review scheduled tasks that launch Java executables from user or temp paths.
- Use memory scanning, since disk-based tools may miss both backdoors.
- Apply Symantec’s and Lab52’s published indicators to hunt for related activity.
Most importantly, treat any confirmed infection as a likely precursor to ransomware. Isolate the host and check for wider access before encryption begins.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!