Attackers used Microsoft Teams vishing calls and Quick Assist remote sessions to gain access to corporate environments, then launched PowerShell-based staging that deployed a Go-based backdoor family dubbed GoGRPC. Zscaler ThreatLabz said the activity was observed from January through June 2026 and likely reflects an initial access broker operation aligned with ransomware follow-on activity, with targeting that increasingly shifted toward higher-value enterprise victims.
Researchers identified four GoGRPC variants—Lep, Giver, Pet, and Kind—that evolved over time with added TLS support, obfuscation, and changes to gRPC-based command-and-control. The malware fingerprints infected hosts, registers with C2 infrastructure, executes reconnaissance, and can work alongside additional tools including BlindDoor, S3Siphon, RevSocket, PyGRPC, and RSOX to provide proxying, tunneling, and broader post-compromise access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
ThreatLabz identified four GoGRPC variants—Lep, Giver, Pet, and Kind—and reported that the malware evolved over time with capabilities such as TLS support, obfuscation, and changes to gRPC-based command-and-control communications. The report said the actor's tooling became more sophisticated and increasingly targeted higher-value corporate environments.
After gaining access, the attackers used PowerShell-based staging to deploy a Go-based backdoor family named GoGRPC and, in some cases, additional malware including BlindDoor, S3Siphon, RevSocket, PyGRPC, and RSOX. The tooling supported host fingerprinting, C2 registration, reconnaissance, and proxying or tunneling functions.
Zscaler ThreatLabz reported a cluster of attacks observed from January through June 2026 in which attackers used Microsoft Teams vishing and Quick Assist remote sessions for initial access. The activity was assessed as likely involving an initial access broker supporting ransomware operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourcemalware.news
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.