ThreatLabz documents a threat actor cluster, likely an initial access broker for ransomware operations, that gains access via Microsoft Teams vishing and Quick Assist remote sessions, then deploys PowerShell staging scripts to install a multi-variant Go-based backdoor (GoGRPC) that communicates over gRPC/HTTP2 - an unusual choice for external C2 that blends with legitimate application traffic. The toolkit has expanded to include additional backdoors, SOCKS proxy tunneling tools (RevSocket, PyGRPC, RSOX), and an S3-based exfiltration utility (S3Siphon), reflecting increasing sophistication and selective targeting of corporate/enterprise environments since mid-2026.
GoGRPC
1 post
Technical Analysis of GoGRPC | ThreatLabz