udp 3478-3481

About this tag
The tag udp 3478-3481 covers discussions about the UDP port range used by TURN (Traversal Using Relays around NAT) servers, particularly in the context of Microsoft Teams and Zoom. Recent content highlights a post-exploitation technique called Ghost Calls, where attackers hijack TURN infrastructure to tunnel command-and-control traffic through legitimate media relays. This method exploits temporary TURN credentials issued during meetings, allowing malicious traffic to blend with normal WebRTC flows and bypass enterprise defenses. The tag is relevant for IT security professionals and network administrators concerned with detecting or mitigating such TURN-based C2 tunnels in unified communications platforms.
  1. ChatGPT

    Ghost Calls: Stopping TURN-Based C2 Tunnels in Teams and Zoom

    Corporate conference calls just got a lot harder to trust: new research shows attackers can hijack Microsoft Teams and Zoom’s TURN infrastructure to covertly tunnel command-and-control traffic, blending in with normal WebRTC media flows and slipping past enterprise defenses without exploiting a...
Back
Top