Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infection

Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections

Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations

Listen to this article

0:00

Press play to start listening

A Microsoft Teams call from someone posing as company IT support can lead an employee to approve a Quick Assist session, giving the attacker remote control of the computer.

Zscaler ThreatLabz has tracked these voice-phishing attacks, commonly called vishing, since January 2026 in which, after gaining access, the attackers use PowerShell to inspect the system to install a new backdoor named GoGRPC

Once the employee approves the Quick Assist session, the attacker can view and control the computer. They then use PowerShell commands to collect information about the device, download malware and configure it to start whenever the user signs in.

The company believes that some attacks may also begin with an email flood that fills the victim’s inbox with unwanted messages. The fake support worker then calls through Teams and offers to solve the apparent email problem. Researchers based this part of their assessment on similar campaigns, not direct confirmation in every GoGRPC case.

GoGRPC Gives Attackers Lasting Access

The main tool documented in Zscaler ThreatLabz’s research is GoGRPC, a backdoor written in the Go programming language. It allows its operator to run commands on an infected computer and use the device as a proxy for further network activity.

However, researchers have also identified four other malware variants and named them Lep, Giver, Pet and Kind. Lep first appeared in January 2026, followed by Giver in February, Pet in April and Kind in June. The names were assigned by the researchers and do not always appear inside the malware files.

According to researchers, each version changes how the backdoor hides its code, identifies infected computers and communicates with attacker-controlled servers. Later versions added encrypted connections and heavier code obfuscation, while removing some features present in earlier builds.

GoGRPC uses gRPC, an open-source universal remote procedure call framework, to receive commands and return results. This communication technology is widely used by legitimate applications, but the attackers employ it as the direct connection between infected computers and their control servers.

Zscaler also found several supporting tools dubbed by researchers as BlindDoor, RevSocket, PyGRPC and RSOX. BlindDoor provides another way to run commands, while RevSocket, PyGRPC and RSOX turn compromised computers into network proxies. These proxies can help attackers reach other systems through the victim’s machine or hidewhere their traffic originates.

Another utility, named S3Siphon, searches common folders such as Desktop, Documents, Downloads, Pictures and OneDrive before uploading selected files to an Amazon S3 bucket. Zscaler said the stolen data could later be used to pressure victims into paying a ransom.

Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections

Campaign May Supply Access for Ransomware

Zscaler assesses that the operator is likely acting as an initial access broker for ransomware attacks. Such brokers compromise business networks and provide that access to other criminals, who may later steal data or deploy ransomware.

The researchers have not identified a specific ransomware family receiving access from this campaign. The connection is based on the victim selection, data theft capabilities and continued development of tools aimed at company networks.

Companies that do not use Quick Assist should block or remove it from employee computers. Microsoft has previously advised organizations to restrict remote-support applications when they are unnecessary and to limit Teams contact from unknown external accounts.

Employees should not accept remote-control requests from anyone who contacts them unexpectedly through Teams. A genuine helpdesk worker should be verified through an internal phone number, support portal or known company contact before any Quick Assist session is approved.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts