Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections
ID: 36769ade-76d0-51e6-b95e-9c949a82d295
STIX ID: report--36769ade-76d0-51e6-b95e-9c949a82d295
Feed Name: HackRead
Threat Score
Zscaler ThreatLabz reports an active vishing campaign (via Microsoft Teams Quick Assist) that tricks employees into approving remote sessions, allowing attackers to deploy a GoGRPC backdoor and supporting tools to run commands, create proxies, and exfiltrate files (via S3Siphon); researchers assess the operator likely acts as an initial-access broker supplying access for ransomware actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
