Date: 07/28/2026
Severity: High
Summary
Since January 2026, ThreatLabz has tracked a threat actor believed to operate as an initial access broker for ransomware campaigns. The actor primarily targets organizations through Microsoft Teams vishing attacks and deploys a Go-based backdoor named GoGRPC. Researchers identified four GoGRPC variants Lep, Giver, Pet, and Kind each with shared features and unique capabilities. The campaigns also employ additional malware, including BlindDoor, RevSocket, PyGRPC, S3Siphon, and RSOX. ThreatLabz analyzed the functionality of these tools along with the command-and-control (C2) communication methods used by the attackers. The findings provide insights into the group's evolving toolkit and techniques used to establish and maintain access in targeted environments.
Indicators of Compromise (IOC) List
Domains/URLs | scansec-upd.com re2.filesdwnload.top re8.dowlfles.online update19.upldf.online xeds.geranteeg.online |
IP Address | 5.253.59.222 94.140.114.192 193.29.57.37 45.86.162.228 46.30.191.126 46.30.191.60 185.82.126.91 |
Hash | 66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5
9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52
7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f
35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc
759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96
f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121
51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33
5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85
65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670
41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91
f85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "re2.filesdwnload.top" or url like "re2.filesdwnload.top" or siteurl like "re2.filesdwnload.top" or domainname like "update19.upldf.online" or url like "update19.upldf.online" or siteurl like "update19.upldf.online" or domainname like "scansec-upd.com" or url like "scansec-upd.com" or siteurl like "scansec-upd.com" or domainname like "re8.dowlfles.online" or url like "re8.dowlfles.online" or siteurl like "re8.dowlfles.online" or domainname like "xeds.geranteeg.online" or url like "xeds.geranteeg.online" or siteurl like "xeds.geranteeg.online" |
Detection Query 2 : | dstipaddress IN ("46.30.191.60","46.30.191.126","193.29.57.37","185.82.126.91","5.253.59.222","94.140.114.192","45.86.162.228") or srcipaddress IN ("46.30.191.60","46.30.191.126","193.29.57.37","185.82.126.91","5.253.59.222","94.140.114.192","45.86.162.228") |
Detection Query 3 : | sha256hash IN ("51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33","9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52","f85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5","66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5","f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121","5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85","41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91","7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f","35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc","759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96","65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670")
|
Reference:
https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor