Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...
Indicators of Compromise
- ip: 94.140.114.192
- ip: 45.86.162.228
- domain: scansec-upd.com
- ip: 5.253.59.222
- hash: 3d1819de80c5a6633bc546f7b07086a4
- hash: 7a818efa2a3af3130a3c4b69260a08aa
- hash: 925dc63fc70de650127f41e00e9ffbf3
- hash: b42366dcf2612adb43ed0c617bfa98d4
- hash: b6a74fcadf1efca4e9f01658529556bc
- hash: 1d93080e7e97cd265e259a5e6f4d76e5583ed211
- hash: 233dbba4110d6d52d5378eb8ca6e8edb5f271445
- hash: 3f25712f02617eda348f1703bb1096e8a121ceaf
- hash: 7ddb7a07d5ecb0056f545306225e7a59a8bc2753
- hash: a6491268ab79940dcbb811c32f1b19a988219814
- hash: 35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc
- hash: 41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91
- hash: 51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33
- hash: 5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85
- hash: 65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670
- hash: 66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5
- hash: 759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96
- hash: 7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f
- hash: 9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52
- hash: f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121
- hash: f85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5
- ip: 193.29.57.37
- ip: 46.30.191.126
- ip: 46.30.191.60
- url: http://re102.fastwinnow.com/download/link
- domain: re102.fastwinnow.com
- domain: re2.filesdwnload.top
- domain: re8.dowlfles.online
- domain: update19.upldf.online
- domain: xeds.geranteeg.online
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Description
Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor"]
- Adversary
- null
- Pulse Id
- 6a678b1bffd8195d4d34ef68
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip94.140.114.192 | — | |
ip45.86.162.228 | — | |
ip5.253.59.222 | — | |
ip193.29.57.37 | — | |
ip46.30.191.126 | — | |
ip46.30.191.60 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainscansec-upd.com | — | |
domainre102.fastwinnow.com | — | |
domainre2.filesdwnload.top | — | |
domainre8.dowlfles.online | — | |
domainupdate19.upldf.online | — | |
domainxeds.geranteeg.online | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash3d1819de80c5a6633bc546f7b07086a4 | — | |
hash7a818efa2a3af3130a3c4b69260a08aa | — | |
hash925dc63fc70de650127f41e00e9ffbf3 | — | |
hashb42366dcf2612adb43ed0c617bfa98d4 | — | |
hashb6a74fcadf1efca4e9f01658529556bc | — | |
hash1d93080e7e97cd265e259a5e6f4d76e5583ed211 | — | |
hash233dbba4110d6d52d5378eb8ca6e8edb5f271445 | — | |
hash3f25712f02617eda348f1703bb1096e8a121ceaf | — | |
hash7ddb7a07d5ecb0056f545306225e7a59a8bc2753 | — | |
hasha6491268ab79940dcbb811c32f1b19a988219814 | — | |
hash35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc | — | |
hash41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91 | — | |
hash51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33 | — | |
hash5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85 | — | |
hash65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670 | — | |
hash66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5 | — | |
hash759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96 | — | |
hash7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f | — | |
hash9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52 | — | |
hashf36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121 | — | |
hashf85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://re102.fastwinnow.com/download/link | — |
Threat ID: 6a6882e39c2644c7f871e320
Added to database: 07/28/2026, 10:22:27 UTC
Last updated: 07/28/2026, 21:37:31 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.