<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor-o72rlfxfb" -->

---
title: Helpdesk Hijackers: Teams Vishing, Quick Assist, and...
description: Zscaler ThreatLabz has been tracking a threat actor operating as an initial access broker for ransomware attacks since January 2026. The attacker uses...
canonical: https://daily.dev/posts/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor-o72rlfxfb
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor | daily.dev
og:description: Zscaler ThreatLabz has been tracking a threat actor operating as an initial access broker for ransomware attacks since January 2026. The attacker uses...
og:url: https://daily.dev/posts/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor-o72rlfxfb
og:image: https://api.daily.dev/og/posts/o72rLFxfb.png
og:image:alt: Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

**[Security Boulevard](https://daily.dev/sources/securityboulevard)** · 15 min read · 0 upvotes · 0 comments

## Summary

Zscaler ThreatLabz has been tracking a threat actor operating as an initial access broker for ransomware attacks since January 2026. The attacker uses Microsoft Teams vishing, impersonating IT helpdesk staff, to convince victims to open Quick Assist remote sessions. After gaining access, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which uses gRPC over HTTP/2 for C2 communication — an unusual choice that helps blend traffic with legitimate HTTP/2 streams. Four GoGRPC variants (Lep, Giver, Pet, Kind) have been identified, each evolving with added obfuscation, TLS support, and increased targeting of corporate environments. Additional tools deployed include BlindDoor (backdoor), S3Siphon (data exfiltration to AWS S3), RevSocket (Go-based WebSocket SOCKS proxy), PyGRPC (Python-based gRPC SOCKS proxy), and RSOX (Rust-based SOCKS proxy relay). The campaign has grown more sophisticated over time, with recent activity using MSI-packaged payloads and selective targeting based on corporate environment fingerprinting. Full IOCs including SHA256 hashes and C2 server addresses are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securityboulevard.com/2026/07/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor>

## Similar posts on daily.dev

- [Ransomware gang abuses Microsoft Teams relays to hide malicious traffic](https://daily.dev/posts/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic-w9qf9jps7) · BleepingComputer · 0 upvotes · 0 comments
- [GoSerpent backdoor attacks in Southeast Asia](https://daily.dev/posts/goserpent-backdoor-attacks-in-southeast-asia-s7okvghei) · Securelist · 13 upvotes · 1 comments
- [New GoGra malware for Linux uses Microsoft Graph API for comms](https://daily.dev/posts/new-gogra-malware-for-linux-uses-microsoft-graph-api-for-comms-vwc7uzrie) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#golang](https://daily.dev/tags/golang), [#malware](https://daily.dev/tags/malware), [#ransomware](https://daily.dev/tags/ransomware), [#grpc](https://daily.dev/tags/grpc)

[View this post on daily.dev](https://daily.dev/posts/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor-o72rlfxfb)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor","url":"https://daily.dev/posts/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor-o72rlfxfb","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor-o72rlfxfb"},"datePublished":"2026-07-27T15:07:25.069Z","dateModified":"2026-07-27T15:07:53.887Z","description":"Zscaler ThreatLabz has been tracking a threat actor operating as an initial access broker for ransomware attacks since January 2026. The attacker uses...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8fe9eeb967de205fd6743e2535f16178?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8fe9eeb967de205fd6743e2535f16178?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Security Boulevard","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Security Boulevard","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/3613c832180040de8d85bb29f74395be","url":"https://daily.dev/sources/securityboulevard"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor-o72rlfxfb","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"golang,malware,ransomware,grpc","timeRequired":"PT15M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Security Boulevard","item":"https://daily.dev/sources/securityboulevard"},{"@type":"ListItem","position":3,"name":"Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor"}]}
```

