Why Web Conferencing Fits Short-Term C2

▶ Watch (0:46)

Crosser defined four ideal attributes for a short-term C2 channel: low latency, high throughput, wide reach on enterprise networks, and trust (allow-listed, excluded from inspection). Web conferencing solutions meet all four. They are designed for real-time communication. Microsoft recommends split tunneling for Teams traffic and excluding its domains from TLS inspection. Zoom makes similar recommendations for Zoom.us. These are not vendor mistakes. The systems need those settings to function.

Reverse Engineering Zoom and Teams

▶ Watch (10:41)

Crosser reverse engineered Zoom and Microsoft Teams using a custom Wireshark analyzer. Zoom uses a custom protocol over RTP on UDP port 8801. Teams uses stock WebRTC with DTLS key exchange and SRTP on UDP port 3478. Both solutions are resilient. In a lab environment with a mandatory TLS-inspecting web proxy as the only egress, Zoom’s desktop client fell back through four connection methods before successfully using a WebSocket channel through the proxy.

Obtaining TURN Credentials

▶ Watch (16:00)

Both Zoom and Teams provide TURN server credentials to clients. Zoom returns them through a WebSocket connection to its real-time web gateway. Teams exposes an authenticated REST endpoint. The credentials are valid for several days. This is not a vulnerability. It is how the solutions function. Crosser noted that once credentials are obtained, the victim system does not need Zoom or Teams installed. The implant can use the TURN infrastructure directly.

Demo: Tunneling Through Zoom and Teams

▶ Watch (24:03)

Crosser demonstrated Turn Tunneler with two components: a controller on the operator system and a relay on the victim system. The controller generates a WebRTC offer. The relay generates an answer. The connection routes through Zoom’s TURN infrastructure. A file download achieved 9-10 MB/s. At the network level, the traffic appeared as a TLS connection to a Zoom.us subdomain on port 443. The Teams demo showed 3-5 MB/s downloads and a remote port forward that exposed a local web server on the victim network.

Optimizing Tunneling Speed

▶ Watch (31:21)

Crosser observed that international routing and peering relationships often matter more than last-mile connection speed. He tested a 40 Mbps residential connection. A direct download from a Singapore server averaged 2 MB/s. Routing through ExpressVPN in Chicago doubled the speed. He warned against tunneling TCP over TCP due to the TCP meltdown problem. He recommended Microsoft Teams for tunneling through compromised help desk users because Microsoft’s global backbone and private transit provide better speeds than direct peer-to-peer connections.

Q&A

Did you find any internal systems reachable through the Zoom or Teams TURN relays? Crosser did not look for that. His focus was C2 tunneling, not internal network access. ▶ 39:55

Why do Microsoft and Zoom allow arbitrary communication through TURN relays? The traffic looks identical to normal WebRTC video traffic at the network level because both use DTLS-encrypted tunnels. ▶ 40:48

Notable Quotes

these solutions are very resilient and are able to egress in many different types of environments Adam “UNC1739” Crosser · ▶ 11:42

at the network level it would just look like the user is joining a video call for 3 hours but we’re actually using that infrastructure as a covert channel Adam “UNC1739” Crosser · ▶ 18:20

we’re getting you know 9 or 10 megabytes per second down on this download here Adam “UNC1739” Crosser · ▶ 25:14

Key Takeaways

  • Turn Tunneler routes C2 traffic through Zoom and Microsoft Teams TURN infrastructure at 3-10 MB/s.
  • Zoom mitigated the technique by restricting TURN connections to media servers only.
  • Microsoft Teams TURN infrastructure still works and benefits from Microsoft’s global backbone.
  • TURN credentials are valid for days and require no victim-side software beyond the implant.

About the Speaker(s)

Adam “UNC1739” Crosser is a Staff Security Engineer at Praetorian, specializing in offensive security research and tooling development. He began his career in red team operations, honing his skills in adversary simulation and advanced attack techniques. Now part of the Praetorian Labs team, Adam focuses on vulnerability research, exploit development, and building custom offensive security capabilities to support red team engagements—pushing the boundaries of adversary tradecraft.