Warning: Vishing Attacks Open the Door to Ransomware Gangs

KnowBe4 Team | Aug 13, 2026

An initial access broker for ransomware gangs is targeting organizations with voice phishing (vishing) attacks through Microsoft Teams, according to researchers at Zscaler’s ThreatLabz.

“From January through June 2026, ThreatLabz examined a cluster of related campaigns that used Microsoft Teams vishing and Quick Assist for initial access, followed by PowerShell-based staging,” the researchers write. “Post-compromise, the threat actor deployed GoGRPC along with various backdoor and proxying tools. Since the beginning of the year, the threat actor’s tooling has increased in sophistication, with more recent activity appearing to be more selective and increasingly focused on corporate environments.”

The attackers begin by flooding the target’s inbox with spam emails in order to make the victim think there’s a technical issue that needs to be fixed. The attackers then contact the victim via Microsoft Teams posing as IT support. Since the victim is already experiencing a technical problem, they’re primed to expect a call from the IT department.

“The initial compromise by this threat actor likely starts with spam bombing the victim’s inbox,” Zscaler says. “This assessment is based on similar campaigns that ThreatLabz has observed (such as Payouts King and other campaigns reported by Microsoft). These vishing attacks use Microsoft Teams, with the threat actor posing as IT/helpdesk staff offering assistance. The objective is to persuade the victim to open a Quick Assist link to establish a remote session.”

Once the attackers have remote access to the victim’s computer, they deploy several strains of malware to establish persistence and escalate privileges within the organization. After establishing a substantial foothold, the threat actor sells the access to ransomware gangs for follow-on attacks.

AI-native security awareness training can give your organization an essential layer of defense against social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce digital workforce risk.

Zscaler has the story: https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.