Zscaler Microsoft Teams Vishing Campaign Deploys GoGRPC Backdoor
Article Content
- •Attackers use vishing via Microsoft Teams to gain remote access to corporate systems.
- •The GoGRPC backdoor allows for command execution and system information collection.
- •Threat actor linked to ransomware operations has been active since January 2026.
A vishing campaign utilizing Microsoft Teams has been identified, targeting organizations through fake IT support calls. Attackers persuade victims to open Quick Assist links, enabling remote access to systems. The primary tool deployed is GoGRPC, a Go-based backdoor capable of executing commands and collecting system information. This threat actor is suspected to be an initial access broker for ransomware operations, with campaigns tracked since January 2026. Multiple variants of GoGRPC have been identified, including Lep, Giver, Pet, and Kind. The campaign has been linked to spam bombing tactics to initiate the compromise. Additional malware tools such as BlindDoor and RevSocket have also been observed in these attacks. The ongoing threat poses significant risks to corporate security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Payouts King and BlindDoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Manipulation Campaigns Exploit Indirect Prompt Injection Techniques Zscaler's ThreatLabz identified two campaigns using indirect prompt injection (IPI) to manipulate AI agents into executing fraudulent actions. The first campaign involves a payment scam disguised as API documentation, tricking AI agents into sending funds to attacker-controlled accounts. The second campaign employs a…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…