logo

Warning: Vishing Attacks Open the Door to Ransomware Gangs

ID: b222ef06-62ec-53b5-8688-da1d39ed502f

STIX ID: report--b222ef06-62ec-53b5-8688-da1d39ed502f

Feed Name: KnowBe4 Blog

Threat Score
75/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

Author: KnowBe4 Team

...
...

Researchers at Zscaler ThreatLabz observed an active campaign (Jan–Jun 2026) where an initial access broker uses spam bombing and Microsoft Teams vishing — posing as IT support — to trick victims into opening Quick Assist remote sessions. Once remote access is obtained the attackers run PowerShell-based staging, deploy GoGRPC backdoors and other tools to establish persistence and escalate privileges, and then sell access to ransomware gangs, with increasingly selective targeting of corporate environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.