Warning: Vishing Attacks Open the Door to Ransomware Gangs
ID: b222ef06-62ec-53b5-8688-da1d39ed502f
STIX ID: report--b222ef06-62ec-53b5-8688-da1d39ed502f
Feed Name: KnowBe4 Blog
Researchers at Zscaler ThreatLabz observed an active campaign (Jan–Jun 2026) where an initial access broker uses spam bombing and Microsoft Teams vishing — posing as IT support — to trick victims into opening Quick Assist remote sessions. Once remote access is obtained the attackers run PowerShell-based staging, deploy GoGRPC backdoors and other tools to establish persistence and escalate privileges, and then sell access to ransomware gangs, with increasingly selective targeting of corporate environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
