Microsoft Teams Vishing Campaign Deploys GoGRPC Backdoor

Microsoft Teams Vishing Campaign Deploys GoGRPC Backdoor

First seen 28 Jul 2026, 10:02 UTC ZscalerCybersecuritynews 70% similarity 69.5

Article Content

Browse articles
ThreatCluster

A vishing campaign utilizing Microsoft Teams has been identified, targeting organizations through fake IT support calls. Attackers persuade victims to open Quick Assist links, enabling remote access to systems. The primary tool deployed is GoGRPC, a Go-based backdoor capable of executing commands and collecting system information. This threat actor is suspected to be an initial access broker for ransomware operations, with campaigns tracked since January 2026. Multiple variants of GoGRPC have been identified, including Lep, Giver, Pet, and Kind. The campaign has been linked to spam bombing tactics to initiate the compromise. Additional malware tools such as BlindDoor and RevSocket have also been observed in these attacks. The ongoing threat poses significant risks to corporate security.

Key Points: • Attackers use vishing via Microsoft Teams to gain remote access to corporate systems. • The GoGRPC backdoor allows for command execution and system information collection. • Threat actor linked to ransomware operations has been active since January 2026.

ThreatCluster AI How this analysis works

Timeline

2026-01-01
Tracking of vishing campaigns begins
Zscaler ThreatLabz starts monitoring a series of vishing attacks linked to ransomware actors using Microsoft Teams.
Zscaler
2026-07-28
Public disclosure of GoGRPC backdoor
Zscaler publishes findings on the GoGRPC backdoor variants and their capabilities, detailing the attack methods used.
Zscaler
2026-07-28
Cybersecurity news coverage
Cybersecuritynews reports on the ongoing vishing campaign and its implications for corporate security.
Cybersecuritynews

Community

Browse all →