Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor

    Date: 07/28/2026

    Severity: High

    Summary

    Since January 2026, ThreatLabz has tracked a threat actor believed to operate as an initial access broker for ransomware campaigns. The actor primarily targets organizations through Microsoft Teams vishing attacks and deploys a Go-based backdoor named GoGRPC. Researchers identified four GoGRPC variants Lep, Giver, Pet, and Kind each with shared features and unique capabilities. The campaigns also employ additional malware, including BlindDoor, RevSocket, PyGRPC, S3Siphon, and RSOX. ThreatLabz analyzed the functionality of these tools along with the command-and-control (C2) communication methods used by the attackers. The findings provide insights into the group's evolving toolkit and techniques used to establish and maintain access in targeted environments.

    Indicators of Compromise (IOC) List 

    Domains/URLs

    scansec-upd.com

    re2.filesdwnload.top

    re8.dowlfles.online

    update19.upldf.online

    xeds.geranteeg.online

    IP Address 

    5.253.59.222

    94.140.114.192

    193.29.57.37

    45.86.162.228

    46.30.191.126

    46.30.191.60

    185.82.126.91

    Hash  

    66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5

    9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52

    7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f

    35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc

    759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96

    f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121

    51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33

    5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85

    65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670

    41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91

    f85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "re2.filesdwnload.top" or url like "re2.filesdwnload.top" or siteurl like "re2.filesdwnload.top" or domainname like "update19.upldf.online" or url like "update19.upldf.online" or siteurl like "update19.upldf.online" or domainname like "scansec-upd.com" or url like "scansec-upd.com" or siteurl like "scansec-upd.com" or domainname like "re8.dowlfles.online" or url like "re8.dowlfles.online" or siteurl like "re8.dowlfles.online" or domainname like "xeds.geranteeg.online" or url like "xeds.geranteeg.online" or siteurl like "xeds.geranteeg.online"

    Detection Query 2 :

    dstipaddress IN ("46.30.191.60","46.30.191.126","193.29.57.37","185.82.126.91","5.253.59.222","94.140.114.192","45.86.162.228") or srcipaddress IN ("46.30.191.60","46.30.191.126","193.29.57.37","185.82.126.91","5.253.59.222","94.140.114.192","45.86.162.228")

    Detection Query 3 :

    sha256hash IN ("51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33","9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52","f85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5","66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5","f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121","5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85","41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91","7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f","35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc","759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96","65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670")

    Reference:    

    https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor                           


    Tags

    MalwareBackdoorPhishingVishingMicrosoftInformation Technology

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags