GoGRPC is a Go-based Windows backdoor used in 2026 by a likely initial access broker associated with Microsoft Teams vishing and Quick Assist social-engineering intrusions against organizations, particularly corporate environments. After remote access is obtained, operators use PowerShell-based staging to download and install GoGRPC, establish persistence through a user Run key, and reduce forensic visibility by clearing PowerShell history. At least four variants have been identified—Lep, Giver, Pet, and Kind—showing iterative development over time, including added obfuscation and TLS support in later versions.
GoGRPC communicates with command-and-control infrastructure using gRPC over HTTP/2 and registers infected hosts with metadata such as host, user, domain, operating system, and architecture before maintaining connectivity through heartbeat traffic. The malware supports arbitrary shell command execution and returns command output to the operator. Observed use includes host and domain reconnaissance, user and group discovery, trust enumeration, Active Directory computer discovery, and security product discovery, consistent with post-compromise assessment and preparation for broader intrusion activity. Earlier variants also included an apparent but unimplemented proxying-related command.
The malware is part of a broader intrusion toolkit that has included additional backdoors, reverse proxy utilities, and exfiltration tools. Campaign activity indicates use in establishing and maintaining footholds that may later be sold to ransomware operators. GoGRPC’s evolution from earlier unencrypted gRPC communications to later TLS-protected and more obfuscated variants reflects increasing operator sophistication and a focus on blending command-and-control traffic into normal enterprise network activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
GoGRPC also gathers other information such as the computer name, user name, machine GUID...
It can then receive commands to run discovery tasks, helping attackers assess whether the victim’s environment is valuable for further intrusion.
The backdoor gathers information such as computer name, username, domain details, Windows version, and security software data.
ThreatLabz analyzed the functionality of these tools along with the command-and-control (C2) communication methods used by the attackers.
GoGRPC communicates with its command-and-control infrastructure through gRPC over HTTP/2, usually on port 443.
The proxy opens a WebSocket connection over TLS to a hardcoded C2 server. Once the connection is established, the threat actor can tunnel TCP traffic through the compromised host.
l’acteur exécute un script PowerShell qui télécharge et installe le backdoor GoGRPC
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor deployed after initial access in Microsoft Teams vishing campaigns to help establish persistence and support post-compromise activity inside corporate environments.
Backdoor used after Quick Assist-based initial access. It establishes persistence via a Run registry key, clears PowerShell history, communicates with C2 over gRPC on HTTP/2 via port 443, registers victims with protobuf messages, sends periodic heartbeats, and executes arbitrary shell commands. Variants show increasing obfuscation and protocol changes.
A Go-based backdoor used after Microsoft Teams vishing and Quick Assist access. It supports command execution, system reconnaissance, persistence via a Windows Registry Run value, and C2 communications over gRPC over HTTP/2; later variants added TLS.
A Go-based backdoor used by a threat actor believed to operate as an initial access broker for ransomware campaigns. It is deployed following Microsoft Teams vishing attacks and is used to establish and maintain access in victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.