Fake IT Support Calls on Teams Deploy GoGRPC Backdoor
Attackers are impersonating IT support staff on Microsoft Teams to socially engineer employees into granting remote access via Microsoft's own Quick Assist tool, a classic vishing (voice phishing) attack vector. Once access is granted, they deploy the GoGRPC backdoor, enabling persistent command execution and network proxying — likely as a precursor to ransomware deployment. This attack exploits employee trust in internal communication platforms and legitimate remote support tools, bypassing traditional perimeter defenses entirely. The human element remains one of the most exploited weaknesses in enterprise security, and the use of trusted, built-in tools makes detection significantly harder. Organizations that lack strict verification procedures for IT support requests are especially vulnerable to this type of initial access broker operation.
Tactical Insight
Immediate actions
- Restrict or disable Microsoft Quick Assist and other remote access tools via Group Policy for users who do not require them for their role.
- Issue an urgent security advisory to all staff reminding them never to grant remote access in response to unsolicited Teams messages or calls, even from apparent IT contacts.
- Block or audit outbound connections to unknown GRPC/proxy endpoints at the network perimeter.
Long-term improvements
- Implement a verified IT support request process requiring employees to initiate support tickets through an official portal before any remote session is permitted.
- Enforce a Zero Trust access model so that even legitimate remote access sessions require multi-factor authentication and are scoped to least-privilege.
- Conduct regular, scenario-based phishing and vishing simulation training to build employee resilience against social engineering tactics.
Detection measures
- Deploy EDR/XDR solutions configured to alert on unusual processes spawned via Quick Assist or other remote desktop tools, particularly GoLang-compiled binaries.
- Enable detailed logging of Microsoft Teams external communications and remote assistance sessions, and feed these into your SIEM for anomaly detection.
- Monitor for unusual outbound network traffic patterns consistent with command-and-control or proxying activity (e.g., persistent GRPC connections to external IPs).