Back to Feed
Threat IntelligenceJul 28, 2026

Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections

Fake IT support calls on Microsoft Teams lead to GoGRPC backdoor infections.

Summary

Attackers are using vishing tactics on Microsoft Teams, posing as IT support to trick employees into granting remote access via Quick Assist. Once inside, they install the GoGRPC backdoor, written in Go, which allows command execution and network proxying. This campaign is suspected to be an initial access broker operation for ransomware attacks, with stolen data potentially used for extortion.

Full text

Security Cyber Attacks Phishing ScamFake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations byWaqasJuly 28, 20263 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening A Microsoft Teams call from someone posing as company IT support can lead an employee to approve a Quick Assist session, giving the attacker remote control of the computer. Zscaler ThreatLabz has tracked these voice-phishing attacks, commonly called vishing, since January 2026 in which, after gaining access, the attackers use PowerShell to inspect the system to install a new backdoor named GoGRPC Once the employee approves the Quick Assist session, the attacker can view and control the computer. They then use PowerShell commands to collect information about the device, download malware and configure it to start whenever the user signs in. The company believes that some attacks may also begin with an email flood that fills the victim’s inbox with unwanted messages. The fake support worker then calls through Teams and offers to solve the apparent email problem. Researchers based this part of their assessment on similar campaigns, not direct confirmation in every GoGRPC case. GoGRPC Gives Attackers Lasting Access The main tool documented in Zscaler ThreatLabz’s research is GoGRPC, a backdoor written in the Go programming language. It allows its operator to run commands on an infected computer and use the device as a proxy for further network activity. However, researchers have also identified four other malware variants and named them Lep, Giver, Pet and Kind. Lep first appeared in January 2026, followed by Giver in February, Pet in April and Kind in June. The names were assigned by the researchers and do not always appear inside the malware files. According to researchers, each version changes how the backdoor hides its code, identifies infected computers and communicates with attacker-controlled servers. Later versions added encrypted connections and heavier code obfuscation, while removing some features present in earlier builds. GoGRPC uses gRPC, an open-source universal remote procedure call framework, to receive commands and return results. This communication technology is widely used by legitimate applications, but the attackers employ it as the direct connection between infected computers and their control servers. Zscaler also found several supporting tools dubbed by researchers as BlindDoor, RevSocket, PyGRPC and RSOX. BlindDoor provides another way to run commands, while RevSocket, PyGRPC and RSOX turn compromised computers into network proxies. These proxies can help attackers reach other systems through the victim’s machine or hidewhere their traffic originates. Another utility, named S3Siphon, searches common folders such as Desktop, Documents, Downloads, Pictures and OneDrive before uploading selected files to an Amazon S3 bucket. Zscaler said the stolen data could later be used to pressure victims into paying a ransom. Campaign May Supply Access for Ransomware Zscaler assesses that the operator is likely acting as an initial access broker for ransomware attacks. Such brokers compromise business networks and provide that access to other criminals, who may later steal data or deploy ransomware. The researchers have not identified a specific ransomware family receiving access from this campaign. The connection is based on the victim selection, data theft capabilities and continued development of tools aimed at company networks. Companies that do not use Quick Assist should block or remove it from employee computers. Microsoft has previously advised organizations to restrict remote-support applications when they are unnecessary and to limit Teams contact from unknown external accounts. Employees should not accept remote-control requests from anyone who contacts them unexpectedly through Teams. A genuine helpdesk worker should be verified through an internal phone number, support portal or known company contact before any Quick Assist session is approved. Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts BlindDoorCyber AttackCyber CrimeCybersecurityFake SupportGoGRPCMalwareMicrosoftMicrosoft TeamsPyGRPCQuick AssistRevSocketRSOXScamZscaler Leave a Reply Cancel reply View Comments (0) Related Posts Read More Security Privacy New Study Shows Google Tracking Persists Even With Privacy Tools A new SafetyDetectives study reveals the surprising extent of Google tracking across the web in the US, UK, Switzerland, and Sweden. Discover how Google Analytics, AdSense, and YouTube embeds collect your data, even when using DuckDuckGo. byDeeba Ahmed Read More Cyber Crime Phishing Scam Scams and Fraud Security Phishing attack on LA County computers; personal data of 756k people stolen The Los Angeles County employees have become the victim of a phishing attack and as a result, the… byPushpa Mishra Read More Security Technology What is the tokenization process and why it is so important? A large number of e-commerce payment platforms use effective payment gateway tools and effectively integrate them with an… byOwais Sultan Read More Security Live Nation Confirms Massive Ticketmaster Data Breach In an SEC filing, Live Nation Entertainment confirmed its subsidiary Ticketmaster suffered a data breach, claiming it will… byWaqas

Indicators of Compromise

  • malware — GoGRPC
  • malware — Lep
  • malware — Giver
  • malware — Pet
  • malware — Kind
  • malware — BlindDoor
  • malware — RevSocket
  • malware — PyGRPC
  • malware — RSOX
  • malware — S3Siphon

Entities

Microsoft Teams (product)Quick Assist (product)gRPC (technology)Microsoft (vendor)Zscaler (vendor)Amazon S3 (technology)