Microsoft Teams Phishing Scams Exploit GoGRPC Backdoor Vulnerabilities
Malicious actors use Microsoft Teams to impersonate IT support, leading to GoGRPC backdoor infections through Quick Assist sessions.
The Attack Method
A malicious actor leveraging Microsoft Teams to impersonate IT support personnel can trick employees into granting remote access through Quick Assist, enabling the deployment of a novel backdoor called GoGRPC. This method, identified by Zscaler ThreatLabz, involves vishing attacks where attackers exploit trust in remote support tools to infiltrate corporate networks.
Social Engineering and Technical Exploitation
The campaign, observed since January 2026, combines social engineering with technical exploitation to compromise systems. During these attacks, victims receive unsolicited Teams calls from individuals claiming to represent internal IT departments. After establishing credibility, the attacker requests permission to initiate a Quick Assist session, which allows them to control the device remotely.
The GoGRPC Backdoor
Once access is granted, the threat actor employs PowerShell scripts to gather system information and deploy the GoGRPC backdoor. This tool, developed in the Go programming language, enables attackers to execute commands and use the infected machine as a proxy for subsequent network activities.
Evolution and Communication Techniques
The GoGRPC framework utilizes gRPC, a widely adopted remote procedure call protocol, to maintain stealth by mimicking legitimate traffic. This approach complicates detection, as the communication protocol is common in enterprise applications.
Additional Malicious Tools
The GoGRPC backdoor is part of a broader suite of malicious tools, including four additional variants—Lep, Giver, Pet, and Kind—each exhibiting evolving techniques for code obfuscation and communication with command-and-control servers. Supporting utilities such as BlindDoor, RevSocket, PyGRPC, and RSOX further expand the attackers’ capabilities, allowing them to execute arbitrary commands, establish network proxies, and conceal their activities.
Data Exfiltration and Network Access
Another tool, S3Siphon, scans for sensitive data in standard directories like the Desktop and Documents folders. Zscaler assesses that the operators behind this campaign likely act as initial access brokers, providing entry points to ransomware groups.
Mitigation and Recommendations
To mitigate risks, organizations are advised to disable or restrict Quick Assist unless strictly necessary. Microsoft has previously recommended limiting Teams interactions with external accounts and enforcing strict verification processes for remote support requests. Employees should be trained to confirm the identity of any individual requesting remote access through official channels, such as internal phone numbers or support portals.
Conclusion
The evolution of GoGRPC and its associated tools highlights the growing sophistication of cybercriminal tactics. As threat actors continue to adapt, enterprises must prioritize endpoint security, user education, and proactive monitoring to counter emerging risks.
This method, identified by Zscaler ThreatLabz, involves vishing attacks where attackers exploit trust in remote support tools to infiltrate corporate networks. Zscaler researchers noted that some incidents may begin with spam campaigns flooding inboxes with irrelevant messages, followed by targeted calls. Zscaler assesses that the operators behind this campaign likely act as initial access brokers, providing entry points to ransomware groups.
