THREAT OPS › Threat News › Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
IntroductionZscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC
MITRE ATT&CK techniques
Indicators of compromise
- re102.fastwinnow.comdomain