logo

Technical Analysis of GoGRPC

ID: 65e482b0-f217-50bb-bfb9-810d6930f7aa

STIX ID: report--65e482b0-f217-50bb-bfb9-810d6930f7aa

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

...
...

**Executive summary:** This technical analysis describes the GoGRPC malware family and related toolset used by a threat actor to gain persistence, perform system reconnaissance, execute arbitrary commands, proxy/tunnel traffic, and exfiltrate data (e.g., via S3Siphon); it documents multiple variants (Lep, Giver, Pet, Kind) and newer tooling (RevSocket, PyGRPC, RSOX), C2 protocols (gRPC over HTTP/2, WebSockets/TLS), protobufs and message flows, and observable indicators and behaviors useful for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.