Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Teams Vishing Attack Exploits Quick Assist

Microsoft Teams Vishing Attack Exploits Quick Assist

Posted on July 28, 2026 By CWS

A recent cyberattack campaign exploiting Microsoft Teams involves deceptive IT support calls to gain unauthorized access to corporate networks. This scheme employs the Quick Assist tool to install GoGRPC, a Go-based backdoor, giving attackers the ability to execute commands and gather system information while maintaining access.

Threat Actor Tactics and Tools

The campaign is attributed to a threat actor potentially serving as an initial access broker for ransomware attacks. Their strategy includes overwhelming targets with email spam, impersonating Microsoft Teams users, and initiating Quick Assist sessions to manipulate employees into complying with illegitimate support requests.

Cybersecurity firm Zscaler uncovered the operation while monitoring activities from January to June 2026. Their analysis reveals that the threat group has enhanced its toolkit and increasingly targets corporate environments. The campaign underscores the risks associated with remote support utilities when users are deceived into granting access.

Technical Details of the Attack

The attack typically starts with a method known as spam bombing, where victims receive numerous disruptive messages. During this confusion, attackers posing as IT helpdesk staff contact the victims via Microsoft Teams, urging them to initiate a Quick Assist session and allow remote access.

Once inside, attackers use PowerShell to deploy additional malicious payloads. The GoGRPC backdoor, once installed, ensures persistence by modifying Windows Registry entries, enabling it to run again upon user login. Zscaler identified four GoGRPC variants—Lep, Giver, Pet, and Kind—each differing in encryption use, code obfuscation, and command execution capabilities.

Mitigation and Security Recommendations

To mitigate the threat, organizations must enforce verification of unexpected support requests via recognized internal channels before initiating remote sessions. Limiting external communications on Microsoft Teams and restricting Quick Assist usage to authorized IT personnel can significantly reduce the risk of falling victim to such scams.

Security teams are advised to monitor for anomalous PowerShell activities, unauthorized Registry entries, and unusual outbound gRPC or WebSocket connections. Implementing robust incident-response protocols can help prevent further exploitation and potential ransomware attacks.

Employees should remain vigilant against unsolicited Teams messages and Quick Assist requests, even if they appear to originate from IT. Early detection and response are crucial to averting the kind of secondary ransomware incidents increasingly observed in similar operations.

For further protection, continuously update security measures and train staff to recognize and report suspicious activities promptly. This proactive approach is vital to defending against evolving cyber threats.

Cyber Security News Tags:Backdoor, cyber attack, Cybersecurity, GoGRPC, IT support scam, Malware, Microsoft Teams, network security, Quick Assist, Ransomware, remote access, threat actor, Vishing, Zscaler

Post navigation

Previous Post: Critical TeamCity Vulnerability Demands Immediate Update
Next Post: AI Aids Discovery of Linux Kernel Vulnerability Exploit

Related Posts

Securden Unified PAM Vulnerability Let Attackers Bypass Authentication Securden Unified PAM Vulnerability Let Attackers Bypass Authentication Cyber Security News
Threat Actors Fake BSODs and Trusted Build Tools to Bypass Defenses and Deploy DCRat Threat Actors Fake BSODs and Trusted Build Tools to Bypass Defenses and Deploy DCRat Cyber Security News
IBM AIX Vulnerabilities Let Remote Attacker Execute Arbitrary Commands IBM AIX Vulnerabilities Let Remote Attacker Execute Arbitrary Commands Cyber Security News
CISA Warns of OpenPLC ScadaBR File Upload Vulnerability Exploited in Attacks CISA Warns of OpenPLC ScadaBR File Upload Vulnerability Exploited in Attacks Cyber Security News
2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now 2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now Cyber Security News
Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Act Security Launches to Tackle AI-Induced Patch Challenges
  • AI Aids Discovery of Linux Kernel Vulnerability Exploit
  • Microsoft Teams Vishing Attack Exploits Quick Assist
  • Critical TeamCity Vulnerability Demands Immediate Update
  • Critical FFmpeg Vulnerabilities Demand Urgent Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Act Security Launches to Tackle AI-Induced Patch Challenges
  • AI Aids Discovery of Linux Kernel Vulnerability Exploit
  • Microsoft Teams Vishing Attack Exploits Quick Assist
  • Critical TeamCity Vulnerability Demands Immediate Update
  • Critical FFmpeg Vulnerabilities Demand Urgent Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark