Technical Analysis of GoGRPC
ID: 65e482b0-f217-50bb-bfb9-810d6930f7aa
STIX ID: report--65e482b0-f217-50bb-bfb9-810d6930f7aa
Feed Name: Zscaler Security Research Blog
**Executive summary:** This technical analysis describes the GoGRPC malware family and related toolset used by a threat actor to gain persistence, perform system reconnaissance, execute arbitrary commands, proxy/tunnel traffic, and exfiltrate data (e.g., via S3Siphon); it documents multiple variants (Lep, Giver, Pet, Kind) and newer tooling (RevSocket, PyGRPC, RSOX), C2 protocols (gRPC over HTTP/2, WebSockets/TLS), protobufs and message flows, and observable indicators and behaviors useful for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
