Helpdesk Hijackers: Teams Vishing and Quick Assist Access Delivering the GoGRPC Backdoor
Source report →The blog analyzes a six-month intrusion campaign attributed to an initial access broker believed to provide ransomware groups with access to compromised environments. The operator gains initial access by flooding the target’s mailbox with unsolicited messages, then impersonating internal IT support through Microsoft Teams. The victim is persuaded to initiate a Quick Assist session, giving the operator remote access to execute PowerShell and deploy a custom Go backdoor tracked as GoGRPC. The deployment command downloads and executes the payload, removes its Mark-of-the-Web metadata, establishes logon persistence through a registry value disguised as an audio driver, and deletes the PowerShell command history.
The report documents four GoGRPC variants that communicate over gRPC and HTTP/2 on port 443. The backdoor profiles the compromised system, registers it with the command-and-control server, maintains periodic heartbeats, and supports interactive reconnaissance and command execution. Later variants introduced encrypted communications and progressively stronger code and protocol obfuscation while removing some earlier fingerprinting and mutex functionality.
The operator also deployed a plaintext socket backdoor, reverse SOCKS proxies written in Go, Python, and Rust, and a collection utility that searches user directories and uploads selected files to cloud object storage. In later activity, the staging process became more selective, profiling security products, domain controllers, and the wider environment before deploying a payload, while delivery shifted from standalone executables to installer packages.
IOCs (26)
Scan your environment for IOCs →SHA256 FILE HASH 11
9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f5266b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed57dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b112151edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce335d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f8565af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a67041748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91f85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5DOMAIN 6
scansec-upd.comre2.filesdwnload.topre8.dowlfles.onlineupdate19.upldf.onlinere102.fastwinnow.comxeds.geranteeg.onlineURL 1
https://re102.fastwinnow.com/download/linkIP ADDRESS 7
5.253.59.22294.140.114.192193.29.57.3745.86.162.22846.30.191.12646.30.191.60185.82.126.91FILE NAME 1
appscreen.logDetections (10)
Enable detections →Connect your environment for suggestions and queries personalized to your security telemetry.
- Executable Files Hidden Using Attrib.exe
- Non Browser Process Beaconing to External Host at a Regular Interval
- Quick Assist Execution Followed by Command Interpreter Activity
- Burst of Registry Queries Against the Windows Version Key
- Cloud Object Storage Traffic Under a Backup Agent User Agent
- PowerShell Command History Wipe Via PSReadLine HistorySavePath
- Logon Autostart Entry Written by the Same Command That Downloaded the Payload
- Autostart Value Named After a Device Driver or Audio Component Pointing to a User-Writable Path
- WebSocket Tunnel Established to a Bare IP Address Endpoint by a Non-Browser Process