Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

94.140.114.192

TLP:CLEAR
Active

IPv4 Address

Description

Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and sy...

Sightings (0)

No sightings recorded yet

Details

Name / Label
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Pattern Type
STIX
Confidence
75%
Valid From
Jul 28, 2026 12:00
Total Sightings
0
Added
Jul 28, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 94.140.114.192

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.