Zscaler
Microsoft Teams Vishing Campaign Deploys GoGRPC Backdoor
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A vishing campaign utilizing Microsoft Teams has been identified, targeting organizations through fake IT support calls. Attackers persuade victims to open Quick Assist links, enabling remote access to systems. The primary tool deployed is GoGRPC, a Go-based backdoor capable of executing commands and collecting system information. This threat actor is suspected to be an initial access broker for ransomware operations, with campaigns tracked since January 2026. Multiple variants of GoGRPC have been identified, including Lep, Giver, Pet, and Kind. The campaign has been linked to spam bombing tactics to initiate the compromise. Additional malware tools such as BlindDoor and RevSocket have also been observed in these attacks. The ongoing threat poses significant risks to corporate security.
Key Points: • Attackers use vishing via Microsoft Teams to gain remote access to corporate systems. • The GoGRPC backdoor allows for command execution and system information collection. • Threat actor linked to ransomware operations has been active since January 2026.