logo

Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections

ID: 36769ade-76d0-51e6-b95e-9c949a82d295

STIX ID: report--36769ade-76d0-51e6-b95e-9c949a82d295

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-07-28

Date Updated: 2026-08-06

Author: Waqas

...
...

Zscaler ThreatLabz reports an active vishing campaign (via Microsoft Teams Quick Assist) that tricks employees into approving remote sessions, allowing attackers to deploy a GoGRPC backdoor and supporting tools to run commands, create proxies, and exfiltrate files (via S3Siphon); researchers assess the operator likely acts as an initial-access broker supplying access for ransomware actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.