Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

0
Medium
Published: 07/27/2026 (07/27/2026, 16:45:15 UTC)
Source: AlienVault OTX General

Description

Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor"]
Adversary
null
Pulse Id
6a678b1bffd8195d4d34ef68
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip94.140.114.192
ip45.86.162.228
ip5.253.59.222
ip193.29.57.37
ip46.30.191.126
ip46.30.191.60

Domain

ValueDescriptionCopy
domainscansec-upd.com
domainre102.fastwinnow.com
domainre2.filesdwnload.top
domainre8.dowlfles.online
domainupdate19.upldf.online
domainxeds.geranteeg.online

Hash

ValueDescriptionCopy
hash3d1819de80c5a6633bc546f7b07086a4
hash7a818efa2a3af3130a3c4b69260a08aa
hash925dc63fc70de650127f41e00e9ffbf3
hashb42366dcf2612adb43ed0c617bfa98d4
hashb6a74fcadf1efca4e9f01658529556bc
hash1d93080e7e97cd265e259a5e6f4d76e5583ed211
hash233dbba4110d6d52d5378eb8ca6e8edb5f271445
hash3f25712f02617eda348f1703bb1096e8a121ceaf
hash7ddb7a07d5ecb0056f545306225e7a59a8bc2753
hasha6491268ab79940dcbb811c32f1b19a988219814
hash35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc
hash41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91
hash51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33
hash5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85
hash65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670
hash66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5
hash759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96
hash7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f
hash9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52
hashf36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121
hashf85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5

Url

ValueDescriptionCopy
urlhttp://re102.fastwinnow.com/download/link

Threat ID: 6a6882e39c2644c7f871e320

Added to database: 07/28/2026, 10:22:27 UTC

Last updated: 07/28/2026, 21:37:31 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses