An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.”
Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks.
Aligning with tactics observed in campaigns such as Payouts King and Microsoft-documented cross-tenant helpdesk impersonation intrusions.
Posing as internal IT support, the attackers persuade users to launch a Quick Assist remote session, effectively granting interactive access.
This social engineering vector mirrors techniques highlighted in Microsoft’s April 2026 report on human-operated intrusions leveraging Teams-based vishing.
Once access is established, the operators execute PowerShell-based staging scripts to profile the host and deploy payloads.
Central to the campaign is GoGRPC, a modular backdoor written in Go that communicates with command-and-control (C2) infrastructure using gRPC over HTTP/2 an uncommon choice for external C2 traffic that helps blend malicious communications with legitimate enterprise traffic on port 443.
ThreatLabz identified four distinct GoGRPC variants Lep, Giver, Pet, and Kind tracked chronologically from January through June 2026. The attack chain begins with targeted “spam bombing,” overwhelming victims with email noise before initiating contact through Microsoft Teams.
While earlier variants such as Lep and Giver include system fingerprinting, mutex-based execution control, and limited obfuscation, later variants (Pet and Kind) introduce stronger stealth mechanisms including TLS-encrypted C2 communication, obfuscated method structures, and removal of identifiable host-based agent IDs.
The Kind variant further modifies protocol endpoints and obfuscates gRPC definitions, signaling active development and operational refinement.
Following execution, GoGRPC establishes persistence via registry Run keys and begins host reconnaissance. It collects detailed system information, including Windows version, domain context, username, hostname, and machine GUID, which is used to uniquely identify infected systems.
The malware then registers with the C2 server using a structured protobuf-based handshake and enters a tasking loop, executing commands such as system enumeration, Active Directory discovery, antivirus inspection, and privilege assessment.
These behaviors strongly indicate pre-ransomware reconnaissance consistent with IAB tradecraft.
Notably, GoGRPC supports arbitrary command execution via the Go os/exec library, returning stdout and stderr outputs to the operator.
While earlier variants defined proxy tunneling capabilities, implementation appears incomplete and was later removed, suggesting a shift toward dedicated proxy tooling.
In parallel with GoGRPC, ThreatLabz observed deployment of multiple auxiliary tools that enhance persistence, lateral movement, and data exfiltration.
These include BlindDoor, a lightweight backdoor using a simple command-response protocol; S3Siphon, a data exfiltration utility targeting user directories and uploading files to attacker-controlled AWS S3 buckets; and several SOCKS proxy frameworks such as RevSocket, PyGRPC, and RSOX.
RevSocket leverages WebSockets over TLS with yamux multiplexing to tunnel traffic, while PyGRPC introduces AES-encrypted gRPC communications.
The most recent addition, RSOX, is a Rust-based proxy that supports dynamic C2 configuration and authenticated session control using JSON-based messaging.
These tools enable flexible post-exploitation routing and covert lateral movement within corporate environments.
A key technical distinction in this campaign is the use of gRPC for external C2 communication, unlike frameworks such as Sliver or Mythic where gRPC is typically confined to internal components.
ThreatLabz notes a clear evolution toward more selective targeting, with newer campaigns incorporating environment-aware PowerShell scripts capable of detecting EDR solutions, identifying domain controllers, and evaluating organizational value before deploying full payload chains.
This progression underscores a strategic pivot toward high-value enterprise targets and reinforces the role of Teams-based social engineering as a growing enterprise attack surface.
The findings highlight the increasing convergence of social engineering, living-off-the-land techniques, and modern protocol abuse in ransomware precursor operations, emphasizing the need for stricter controls around remote support tools and enterprise messaging platforms.
| Indicator | Description |
|---|---|
| 66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5 | SHA256 Giver backdoor |
| 9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52 | SHA256 Lep backdoor |
| 7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f | SHA256 Giver backdoor |
| 35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc | SHA256 Pet backdoor (TLS) |
| 759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96 | SHA256 Pet backdoor (TLS) |
| f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121 | SHA256 Kind backdoor (TLS) |
| 51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33 | SHA256 Kind backdoor (TLS) |
| 5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85 | SHA256 RevSocket (alone) |
| 65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670 | SHA256 PyGRPC and reconnaissance |
| 41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91 | SHA256 MSI dropping RSOX |
| f85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5 | SHA256 RSOX |
| scansec-upd[.]com | C2 server deploying tools |
| re2.filesdwnload[.]top | C2 server deploying tools (April) |
| re8.dowlfles[.]online | C2 server deploying tools (May) |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What Features Should AI SOC Have in 2026? A Complete Checklist : Download the AI SOC Features Checklist
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS…
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…
GitLab has issued an emergency security update to address two critical vulnerabilities that could lead…