New GoGRPC malware used in Microsoft Teams vishing attacks

 

New GoGRPC malware used in Microsoft Teams vishing attacks

Zscaler ThreatLabz has released a report detailing activities of a threat actor believed to be operating as an initial access broker for ransomware groups since January 2026. The campaign targets organizations through Microsoft Teams vishing attacks, where attackers impersonate IT or helpdesk staff and convince victims to start a Quick Assist remote support session.

After gaining access, the attackers use PowerShell scripts to collect system information, identify antivirus and endpoint detection tools, fingerprint corporate environments, and deliver additional malware. The main payload is a Go-based backdoor named GoGRPC, which communicates with its command-and-control (C&C) infrastructure using gRPC instead of the HTTP-based protocols commonly used by malware.

ThreatLabz discovered four GoGRPC variants they named Lep, Giver, Pet, and Kind, each with similar core functions but different implementations and capabilities.

Researchers noted that GoGRPC is under active development, with new variants adding or removing features to improve operations in enterprise networks. The malware's increasing focus on corporate environments suggests it is being adapted to support ransomware attacks.

The threat actor also deploys several additional malware families depending on the victim's environment, including BlindDoor, a backdoor designed to maintain persistent communication with the C&C server by automatically reconnecting after disconnections. Other tools include RevSocket and PyGRPC (provide reverse SOCKS proxy capabilities using gRPC or WebSockets, RSOX), and a data theft utility called S3Siphon.

S3Siphon searches common user directories, including Desktop, Documents, Downloads, Pictures, Videos, Music, and OneDrive folders, and exfiltrates collected files by uploading them to an Amazon S3 bucket.

“Since June 2026, the threat actor has been deploying the Kind GoGRPC variant and other new malware tooling (including RevSocket, PyGRPC, and RSOX),” the report notes. “However, the threat actor appears to be more selective in targeting with the use of more sophisticated PowerShell scripts to assess the potential value of the victim and environment before proceeding.”

Additionally, the attackers use PowerShell scripts that perform system reconnaissance, detect domain controllers, gather sensitive information, establish persistence through Windows Registry keys, and download second-stage payloads.

ThreatLabz believes the attacks often begin with spam bombing a victim's inbox before the Microsoft Teams call, a technique previously observed in similar social engineering campaigns.

Back to the list