Skip to content
Microsoft Teams Vishing Campaign Deploys GoGRPC Backdoor

Microsoft Teams Vishing Campaign Deploys GoGRPC Backdoor

First seen 28 Jul 2026, 10:02 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 29, 2026 at 05:12 UTC
  • Attackers use vishing via Microsoft Teams to gain remote access to corporate systems.
  • The GoGRPC backdoor allows for command execution and system information collection.
  • Threat actor linked to ransomware operations has been active since January 2026.

A vishing campaign utilizing Microsoft Teams has been identified, targeting organizations through fake IT support calls. Attackers persuade victims to open Quick Assist links, enabling remote access to systems. The primary tool deployed is GoGRPC, a Go-based backdoor capable of executing commands and collecting system information. This threat actor is suspected to be an initial access broker for ransomware operations, with campaigns tracked since January 2026. Multiple variants of GoGRPC have been identified, including Lep, Giver, Pet, and Kind. The campaign has been linked to spam bombing tactics to initiate the compromise. Additional malware tools such as BlindDoor and RevSocket have also been observed in these attacks. The ongoing threat poses significant risks to corporate security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2026-01-01
Tracking of vishing campaigns begins
Zscaler ThreatLabz starts monitoring a series of vishing attacks linked to ransomware actors using Microsoft Teams.
Zscaler
2026-07-28
Public disclosure of GoGRPC backdoor
Zscaler publishes findings on the GoGRPC backdoor variants and their capabilities, detailing the attack methods used.
Zscaler
2026-07-28
Cybersecurity news coverage
Cybersecuritynews reports on the ongoing vishing campaign and its implications for corporate security.
Cybersecuritynews

More articles in this cluster (4)

Following this threat?

Track Payouts King and BlindDoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed