← All briefs
high August 3, 2026

Helpdesk Hijackers: Teams Vishing and Quick Assist Access Delivering the GoGRPC Backdoor

Source report →

The blog analyzes a six-month intrusion campaign attributed to an initial access broker believed to provide ransomware groups with access to compromised environments. The operator gains initial access by flooding the target’s mailbox with unsolicited messages, then impersonating internal IT support through Microsoft Teams. The victim is persuaded to initiate a Quick Assist session, giving the operator remote access to execute PowerShell and deploy a custom Go backdoor tracked as GoGRPC. The deployment command downloads and executes the payload, removes its Mark-of-the-Web metadata, establishes logon persistence through a registry value disguised as an audio driver, and deletes the PowerShell command history.

The report documents four GoGRPC variants that communicate over gRPC and HTTP/2 on port 443. The backdoor profiles the compromised system, registers it with the command-and-control server, maintains periodic heartbeats, and supports interactive reconnaissance and command execution. Later variants introduced encrypted communications and progressively stronger code and protocol obfuscation while removing some earlier fingerprinting and mutex functionality.

The operator also deployed a plaintext socket backdoor, reverse SOCKS proxies written in Go, Python, and Rust, and a collection utility that searches user directories and uploads selected files to cloud object storage. In later activity, the staging process became more selective, profiling security products, domain controllers, and the wider environment before deploying a payload, while delivery shifted from standalone executables to installer packages.

SHA256 FILE HASH 11
9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52
66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5
7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372f
35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedc
759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96
f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121
51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33
5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85
65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670
41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91
f85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5
DOMAIN 6
scansec-upd.com
re2.filesdwnload.top
re8.dowlfles.online
update19.upldf.online
re102.fastwinnow.com
xeds.geranteeg.online
URL 1
https://re102.fastwinnow.com/download/link
IP ADDRESS 7
5.253.59.222
94.140.114.192
193.29.57.37
45.86.162.228
46.30.191.126
46.30.191.60
185.82.126.91
FILE NAME 1
appscreen.log

Detections (10)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • Executable Files Hidden Using Attrib.exe
  • Non Browser Process Beaconing to External Host at a Regular Interval
  • Quick Assist Execution Followed by Command Interpreter Activity
  • Burst of Registry Queries Against the Windows Version Key
  • Cloud Object Storage Traffic Under a Backup Agent User Agent
  • PowerShell Command History Wipe Via PSReadLine HistorySavePath
  • Logon Autostart Entry Written by the Same Command That Downloaded the Payload
  • Autostart Value Named After a Device Driver or Audio Component Pointing to a User-Writable Path
  • WebSocket Tunnel Established to a Bare IP Address Endpoint by a Non-Browser Process