Friday, September 11, 2026

Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor

An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.”

Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks.

Aligning with tactics observed in campaigns such as Payouts King and Microsoft-documented cross-tenant helpdesk impersonation intrusions.

Posing as internal IT support, the attackers persuade users to launch a Quick Assist remote session, effectively granting interactive access.

This social engineering vector mirrors techniques highlighted in Microsoft’s April 2026 report on human-operated intrusions leveraging Teams-based vishing.

Once access is established, the operators execute PowerShell-based staging scripts to profile the host and deploy payloads.

Central to the campaign is GoGRPC, a modular backdoor written in Go that communicates with command-and-control (C2) infrastructure using gRPC over HTTP/2 an uncommon choice for external C2 traffic that helps blend malicious communications with legitimate enterprise traffic on port 443.

ThreatLabz identified four distinct GoGRPC variants Lep, Giver, Pet, and Kind tracked chronologically from January through June 2026. The attack chain begins with targeted “spam bombing,” overwhelming victims with email noise before initiating contact through Microsoft Teams.

While earlier variants such as Lep and Giver include system fingerprinting, mutex-based execution control, and limited obfuscation, later variants (Pet and Kind) introduce stronger stealth mechanisms including TLS-encrypted C2 communication, obfuscated method structures, and removal of identifiable host-based agent IDs.

The Kind variant further modifies protocol endpoints and obfuscates gRPC definitions, signaling active development and operational refinement.

High-level campaign attack flow and associated tooling for GoGRPC (Source : Zscaler).
High-level campaign attack flow and associated tooling for GoGRPC (Source : Zscaler).

Following execution, GoGRPC establishes persistence via registry Run keys and begins host reconnaissance. It collects detailed system information, including Windows version, domain context, username, hostname, and machine GUID, which is used to uniquely identify infected systems.

The malware then registers with the C2 server using a structured protobuf-based handshake and enters a tasking loop, executing commands such as system enumeration, Active Directory discovery, antivirus inspection, and privilege assessment.

These behaviors strongly indicate pre-ransomware reconnaissance consistent with IAB tradecraft.

Notably, GoGRPC supports arbitrary command execution via the Go os/exec library, returning stdout and stderr outputs to the operator.

While earlier variants defined proxy tunneling capabilities, implementation appears incomplete and was later removed, suggesting a shift toward dedicated proxy tooling.

GoGRPC Backdoor Deployed

In parallel with GoGRPC, ThreatLabz observed deployment of multiple auxiliary tools that enhance persistence, lateral movement, and data exfiltration.

These include BlindDoor, a lightweight backdoor using a simple command-response protocol; S3Siphon, a data exfiltration utility targeting user directories and uploading files to attacker-controlled AWS S3 buckets; and several SOCKS proxy frameworks such as RevSocket, PyGRPC, and RSOX.

RevSocket leverages WebSockets over TLS with yamux multiplexing to tunnel traffic, while PyGRPC introduces AES-encrypted gRPC communications.

The most recent addition, RSOX, is a Rust-based proxy that supports dynamic C2 configuration and authenticated session control using JSON-based messaging.

Communication protocol used by BlindDoor (Source : Zscaler).
Communication protocol used by BlindDoor (Source : Zscaler).

These tools enable flexible post-exploitation routing and covert lateral movement within corporate environments.

A key technical distinction in this campaign is the use of gRPC for external C2 communication, unlike frameworks such as Sliver or Mythic where gRPC is typically confined to internal components.

ThreatLabz notes a clear evolution toward more selective targeting, with newer campaigns incorporating environment-aware PowerShell scripts capable of detecting EDR solutions, identifying domain controllers, and evaluating organizational value before deploying full payload chains.

This progression underscores a strategic pivot toward high-value enterprise targets and reinforces the role of Teams-based social engineering as a growing enterprise attack surface.

The findings highlight the increasing convergence of social engineering, living-off-the-land techniques, and modern protocol abuse in ransomware precursor operations, emphasizing the need for stricter controls around remote support tools and enterprise messaging platforms.

Indicators Of Compromise (IOCs)

IndicatorDescription
66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5SHA256 Giver backdoor
9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52SHA256 Lep backdoor
7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372fSHA256 Giver backdoor
35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedcSHA256 Pet backdoor (TLS)
759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96SHA256 Pet backdoor (TLS)
f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121SHA256 Kind backdoor (TLS)
51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33SHA256 Kind backdoor (TLS)
5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85SHA256 RevSocket (alone)
65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670SHA256 PyGRPC and reconnaissance 
41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91SHA256 MSI dropping RSOX
f85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5 SHA256 RSOX
scansec-upd[.]comC2 server deploying tools
re2.filesdwnload[.]topC2 server deploying tools (April)
re8.dowlfles[.]onlineC2 server deploying tools (May)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What Features Should AI SOC Have in 2026? A Complete Checklist Download the AI SOC Features Checklist

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News