Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...
AI Analysis
Technical Summary
This threat involves a multi-stage attack starting with social engineering via Microsoft Teams vishing, where attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Post-compromise, PowerShell scripts deploy the GoGRPC backdoor in four variants (Lep, Giver, Pet, Kind) that communicate with command-and-control servers using gRPC over HTTP/2, an uncommon protocol that helps evade detection by blending with legitimate traffic. The attackers also use additional tools such as BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies for network pivoting, S3Siphon for data exfiltration, and RSOX proxy relay. The campaign shows increased sophistication with enhanced PowerShell scripts that include antivirus detection, domain controller fingerprinting, and system reconnaissance capabilities. The threat actor likely operates as an initial access broker for ransomware groups, focusing on corporate targets.
Potential Impact
Successful exploitation leads to remote compromise of corporate systems via social engineering and Quick Assist remote sessions. The deployed GoGRPC backdoor and associated tools enable persistent access, network pivoting, reconnaissance, and data exfiltration. The use of uncommon communication protocols (gRPC over HTTP/2) and advanced PowerShell scripts increases the difficulty of detection and mitigation. This can facilitate subsequent ransomware attacks or other malicious activities by downstream threat actors.
Mitigation Recommendations
No official patch or fix is available as this attack relies on social engineering and post-compromise tooling. Organizations should educate users to recognize vishing attempts, especially those impersonating IT helpdesk staff. Restrict or monitor Quick Assist usage and remote assistance sessions. Employ network monitoring for unusual gRPC over HTTP/2 traffic patterns. Use endpoint detection solutions capable of identifying PowerShell script abuse and the presence of known backdoors like GoGRPC and BlindDoor. Since this is not a software vulnerability but a multi-stage attack involving social engineering and malware deployment, focus on user awareness and detection capabilities. Patch status is not yet confirmed — check vendor advisories and security research updates for any emerging mitigations.
Indicators of Compromise
- ip: 94.140.114.192
- ip: 45.86.162.228
- domain: scansec-upd.com
- ip: 5.253.59.222
- hash: 3d1819de80c5a6633bc546f7b07086a4
- hash: 7a818efa2a3af3130a3c4b69260a08aa
- hash: 925dc63fc70de650127f41e00e9ffbf3
- hash: b42366dcf2612adb43ed0c617bfa98d4
- hash: b6a74fcadf1efca4e9f01658529556bc
- hash: 1d93080e7e97cd265e259a5e6f4d76e5583ed211
- hash: 233dbba4110d6d52d5378eb8ca6e8edb5f271445
- hash: 3f25712f02617eda348f1703bb1096e8a121ceaf
- hash: 7ddb7a07d5ecb0056f545306225e7a59a8bc2753
- hash: a6491268ab79940dcbb811c32f1b19a988219814
- hash: 35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc
- hash: 41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91
- hash: 51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33
- hash: 5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85
- hash: 65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670
- hash: 66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5
- hash: 759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96
- hash: 7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f
- hash: 9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52
- hash: f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121
- hash: f85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5
- ip: 193.29.57.37
- ip: 46.30.191.126
- ip: 46.30.191.60
- url: http://re102.fastwinnow.com/download/link
- domain: re102.fastwinnow.com
- domain: re2.filesdwnload.top
- domain: re8.dowlfles.online
- domain: update19.upldf.online
- domain: xeds.geranteeg.online
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Description
Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a multi-stage attack starting with social engineering via Microsoft Teams vishing, where attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Post-compromise, PowerShell scripts deploy the GoGRPC backdoor in four variants (Lep, Giver, Pet, Kind) that communicate with command-and-control servers using gRPC over HTTP/2, an uncommon protocol that helps evade detection by blending with legitimate traffic. The attackers also use additional tools such as BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies for network pivoting, S3Siphon for data exfiltration, and RSOX proxy relay. The campaign shows increased sophistication with enhanced PowerShell scripts that include antivirus detection, domain controller fingerprinting, and system reconnaissance capabilities. The threat actor likely operates as an initial access broker for ransomware groups, focusing on corporate targets.
Potential Impact
Successful exploitation leads to remote compromise of corporate systems via social engineering and Quick Assist remote sessions. The deployed GoGRPC backdoor and associated tools enable persistent access, network pivoting, reconnaissance, and data exfiltration. The use of uncommon communication protocols (gRPC over HTTP/2) and advanced PowerShell scripts increases the difficulty of detection and mitigation. This can facilitate subsequent ransomware attacks or other malicious activities by downstream threat actors.
Defensive Guidance
No official patch or fix is available as this attack relies on social engineering and post-compromise tooling. Organizations should educate users to recognize vishing attempts, especially those impersonating IT helpdesk staff. Restrict or monitor Quick Assist usage and remote assistance sessions. Employ network monitoring for unusual gRPC over HTTP/2 traffic patterns. Use endpoint detection solutions capable of identifying PowerShell script abuse and the presence of known backdoors like GoGRPC and BlindDoor. Since this is not a software vulnerability but a multi-stage attack involving social engineering and malware deployment, focus on user awareness and detection capabilities. Patch status is not yet confirmed — check vendor advisories and security research updates for any emerging mitigations.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor"]
- Pulse Id
- 6a678b1bffd8195d4d34ef68
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip94.140.114.192 | — | |
ip45.86.162.228 | — | |
ip5.253.59.222 | — | |
ip193.29.57.37 | — | |
ip46.30.191.126 | — | |
ip46.30.191.60 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainscansec-upd.com | — | |
domainre102.fastwinnow.com | — | |
domainre2.filesdwnload.top | — | |
domainre8.dowlfles.online | — | |
domainupdate19.upldf.online | — | |
domainxeds.geranteeg.online | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash3d1819de80c5a6633bc546f7b07086a4 | — | |
hash7a818efa2a3af3130a3c4b69260a08aa | — | |
hash925dc63fc70de650127f41e00e9ffbf3 | — | |
hashb42366dcf2612adb43ed0c617bfa98d4 | — | |
hashb6a74fcadf1efca4e9f01658529556bc | — | |
hash1d93080e7e97cd265e259a5e6f4d76e5583ed211 | — | |
hash233dbba4110d6d52d5378eb8ca6e8edb5f271445 | — | |
hash3f25712f02617eda348f1703bb1096e8a121ceaf | — | |
hash7ddb7a07d5ecb0056f545306225e7a59a8bc2753 | — | |
hasha6491268ab79940dcbb811c32f1b19a988219814 | — | |
hash35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc | — | |
hash41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91 | — | |
hash51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33 | — | |
hash5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85 | — | |
hash65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670 | — | |
hash66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5 | — | |
hash759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96 | — | |
hash7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f | — | |
hash9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52 | — | |
hashf36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121 | — | |
hashf85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://re102.fastwinnow.com/download/link | — |
Threat ID: 6a6882e39c2644c7f871e320
Added to database: 07/28/2026, 10:22:27 UTC
Last enriched: 07/31/2026, 12:44:29 UTC
Last updated: 09/10/2026, 18:52:35 UTC
Views: 119
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.