Cyber Security News

Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor

An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.”

Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks.

Aligning with tactics observed in campaigns such as Payouts King and Microsoft-documented cross-tenant helpdesk impersonation intrusions.

Posing as internal IT support, the attackers persuade users to launch a Quick Assist remote session, effectively granting interactive access.

This social engineering vector mirrors techniques highlighted in Microsoft’s April 2026 report on human-operated intrusions leveraging Teams-based vishing.

Once access is established, the operators execute PowerShell-based staging scripts to profile the host and deploy payloads.

Central to the campaign is GoGRPC, a modular backdoor written in Go that communicates with command-and-control (C2) infrastructure using gRPC over HTTP/2 an uncommon choice for external C2 traffic that helps blend malicious communications with legitimate enterprise traffic on port 443.

ThreatLabz identified four distinct GoGRPC variants Lep, Giver, Pet, and Kind tracked chronologically from January through June 2026. The attack chain begins with targeted “spam bombing,” overwhelming victims with email noise before initiating contact through Microsoft Teams.

While earlier variants such as Lep and Giver include system fingerprinting, mutex-based execution control, and limited obfuscation, later variants (Pet and Kind) introduce stronger stealth mechanisms including TLS-encrypted C2 communication, obfuscated method structures, and removal of identifiable host-based agent IDs.

The Kind variant further modifies protocol endpoints and obfuscates gRPC definitions, signaling active development and operational refinement.

High-level campaign attack flow and associated tooling for GoGRPC (Source : Zscaler).

Following execution, GoGRPC establishes persistence via registry Run keys and begins host reconnaissance. It collects detailed system information, including Windows version, domain context, username, hostname, and machine GUID, which is used to uniquely identify infected systems.

The malware then registers with the C2 server using a structured protobuf-based handshake and enters a tasking loop, executing commands such as system enumeration, Active Directory discovery, antivirus inspection, and privilege assessment.

These behaviors strongly indicate pre-ransomware reconnaissance consistent with IAB tradecraft.

Notably, GoGRPC supports arbitrary command execution via the Go os/exec library, returning stdout and stderr outputs to the operator.

While earlier variants defined proxy tunneling capabilities, implementation appears incomplete and was later removed, suggesting a shift toward dedicated proxy tooling.

GoGRPC Backdoor Deployed

In parallel with GoGRPC, ThreatLabz observed deployment of multiple auxiliary tools that enhance persistence, lateral movement, and data exfiltration.

These include BlindDoor, a lightweight backdoor using a simple command-response protocol; S3Siphon, a data exfiltration utility targeting user directories and uploading files to attacker-controlled AWS S3 buckets; and several SOCKS proxy frameworks such as RevSocket, PyGRPC, and RSOX.

RevSocket leverages WebSockets over TLS with yamux multiplexing to tunnel traffic, while PyGRPC introduces AES-encrypted gRPC communications.

The most recent addition, RSOX, is a Rust-based proxy that supports dynamic C2 configuration and authenticated session control using JSON-based messaging.

Communication protocol used by BlindDoor (Source : Zscaler).

These tools enable flexible post-exploitation routing and covert lateral movement within corporate environments.

A key technical distinction in this campaign is the use of gRPC for external C2 communication, unlike frameworks such as Sliver or Mythic where gRPC is typically confined to internal components.

ThreatLabz notes a clear evolution toward more selective targeting, with newer campaigns incorporating environment-aware PowerShell scripts capable of detecting EDR solutions, identifying domain controllers, and evaluating organizational value before deploying full payload chains.

This progression underscores a strategic pivot toward high-value enterprise targets and reinforces the role of Teams-based social engineering as a growing enterprise attack surface.

The findings highlight the increasing convergence of social engineering, living-off-the-land techniques, and modern protocol abuse in ransomware precursor operations, emphasizing the need for stricter controls around remote support tools and enterprise messaging platforms.

Indicators Of Compromise (IOCs)

IndicatorDescription
66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5SHA256 Giver backdoor
9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52SHA256 Lep backdoor
7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372fSHA256 Giver backdoor
35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedcSHA256 Pet backdoor (TLS)
759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96SHA256 Pet backdoor (TLS)
f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121SHA256 Kind backdoor (TLS)
51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33SHA256 Kind backdoor (TLS)
5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85SHA256 RevSocket (alone)
65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670SHA256 PyGRPC and reconnaissance
41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91SHA256 MSI dropping RSOX
f85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5 SHA256 RSOX
scansec-upd[.]comC2 server deploying tools
re2.filesdwnload[.]topC2 server deploying tools (April)
re8.dowlfles[.]onlineC2 server deploying tools (May)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What Features Should AI SOC Have in 2026? A Complete Checklist Download the AI SOC Features Checklist

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…

5 hours ago

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…

5 hours ago

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS…

5 hours ago

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…

6 hours ago

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…

6 hours ago

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead…

7 hours ago