Skip to main content

Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

0
Medium
Published: 07/27/2026 (07/27/2026, 16:45:15 UTC)
Source: AlienVault OTX General

Description

Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 12:44:29 UTC

Technical Analysis

This threat involves a multi-stage attack starting with social engineering via Microsoft Teams vishing, where attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Post-compromise, PowerShell scripts deploy the GoGRPC backdoor in four variants (Lep, Giver, Pet, Kind) that communicate with command-and-control servers using gRPC over HTTP/2, an uncommon protocol that helps evade detection by blending with legitimate traffic. The attackers also use additional tools such as BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies for network pivoting, S3Siphon for data exfiltration, and RSOX proxy relay. The campaign shows increased sophistication with enhanced PowerShell scripts that include antivirus detection, domain controller fingerprinting, and system reconnaissance capabilities. The threat actor likely operates as an initial access broker for ransomware groups, focusing on corporate targets.

Potential Impact

Successful exploitation leads to remote compromise of corporate systems via social engineering and Quick Assist remote sessions. The deployed GoGRPC backdoor and associated tools enable persistent access, network pivoting, reconnaissance, and data exfiltration. The use of uncommon communication protocols (gRPC over HTTP/2) and advanced PowerShell scripts increases the difficulty of detection and mitigation. This can facilitate subsequent ransomware attacks or other malicious activities by downstream threat actors.

Defensive Guidance

No official patch or fix is available as this attack relies on social engineering and post-compromise tooling. Organizations should educate users to recognize vishing attempts, especially those impersonating IT helpdesk staff. Restrict or monitor Quick Assist usage and remote assistance sessions. Employ network monitoring for unusual gRPC over HTTP/2 traffic patterns. Use endpoint detection solutions capable of identifying PowerShell script abuse and the presence of known backdoors like GoGRPC and BlindDoor. Since this is not a software vulnerability but a multi-stage attack involving social engineering and malware deployment, focus on user awareness and detection capabilities. Patch status is not yet confirmed — check vendor advisories and security research updates for any emerging mitigations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor"]
Pulse Id
6a678b1bffd8195d4d34ef68

Indicators of Compromise

Ip

ValueDescriptionCopy
ip94.140.114.192
ip45.86.162.228
ip5.253.59.222
ip193.29.57.37
ip46.30.191.126
ip46.30.191.60

Domain

ValueDescriptionCopy
domainscansec-upd.com
domainre102.fastwinnow.com
domainre2.filesdwnload.top
domainre8.dowlfles.online
domainupdate19.upldf.online
domainxeds.geranteeg.online

Hash

ValueDescriptionCopy
hash3d1819de80c5a6633bc546f7b07086a4
hash7a818efa2a3af3130a3c4b69260a08aa
hash925dc63fc70de650127f41e00e9ffbf3
hashb42366dcf2612adb43ed0c617bfa98d4
hashb6a74fcadf1efca4e9f01658529556bc
hash1d93080e7e97cd265e259a5e6f4d76e5583ed211
hash233dbba4110d6d52d5378eb8ca6e8edb5f271445
hash3f25712f02617eda348f1703bb1096e8a121ceaf
hash7ddb7a07d5ecb0056f545306225e7a59a8bc2753
hasha6491268ab79940dcbb811c32f1b19a988219814
hash35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc
hash41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91
hash51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33
hash5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85
hash65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670
hash66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5
hash759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96
hash7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f
hash9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52
hashf36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121
hashf85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5

Url

ValueDescriptionCopy
urlhttp://re102.fastwinnow.com/download/link

Threat ID: 6a6882e39c2644c7f871e320

Added to database: 07/28/2026, 10:22:27 UTC

Last enriched: 07/31/2026, 12:44:29 UTC

Last updated: 09/10/2026, 18:52:35 UTC

Views: 119

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses