ThreatLabz documents a threat actor cluster, likely an initial access broker for ransomware operations, that gains access via Microsoft Teams vishing and Quick Assist remote sessions, then deploys PowerShell staging scripts to install a multi-variant Go-based backdoor (GoGRPC) that communicates over gRPC/HTTP2 - an unusual choice for external C2 that blends with legitimate application traffic. The toolkit has expanded to include additional backdoors, SOCKS proxy tunneling tools (RevSocket, PyGRPC, RSOX), and an S3-based exfiltration utility (S3Siphon), reflecting increasing sophistication and selective targeting of corporate/enterprise environments since mid-2026.
Ransomware Precursor
3 posts
Technical Analysis of GoGRPC | ThreatLabz US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data ANY.RUN's Malware Trends Tracker data shows that phishing-as-a-service kits now dominate the US threat landscape, with five of the top ten threats being AiTM or device-code phishing platforms that defeat MFA by stealing session cookies or OAuth tokens. Commodity RATs and info stealers remain in constant high-volume circulation, while legacy threats like Emotet and WannaCry persist on unpatched systems. Several top-ranked threats (Cobalt Strike, Qbot, Emotet, DonutLoader, Smoke Loader) function as ransomware precursors, meaning their detection should trigger urgent escalation rather than routine handling.
They Got In Through SonicWall. Then They Tried to Kill Every Security Tool Threat actors breached a network via compromised SonicWall SSLVPN credentials and deployed a sophisticated EDR killer to blind endpoint security prior to a planned ransomware deployment. The malware utilizes a Bring Your Own Vulnerable Driver (BYOVD) technique, dropping a revoked EnCase forensic driver encoded with a novel wordlist substitution cipher to terminate 59 different security processes directly from kernel mode.