THREATOPS
THREAT OPSThreat News › Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

medzscaler_threatlabzPublished 2026-07-27

IntroductionZscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor