An initial access broker for ransomware gangs is targeting organizations with voice phishing (vishing) attacks through Microsoft Teams, according to researchers at Zscaler’s ThreatLabz.
“From January through June 2026, ThreatLabz examined a cluster of related campaigns that used Microsoft Teams vishing and Quick Assist for initial access, followed by PowerShell-based staging,” the researchers write. “Post-compromise, the threat actor deployed GoGRPC along with various backdoor and proxying tools. Since the beginning of the year, the threat actor’s tooling has increased in sophistication, with more recent activity appearing to be more selective and increasingly focused on corporate environments.”
The attackers begin by flooding the target’s inbox with spam emails in order to make the victim think there’s a technical issue that needs to be fixed. The attackers then contact the victim via Microsoft Teams posing as IT support. Since the victim is already experiencing a technical problem, they’re primed to expect a call from the IT department.
“The initial compromise by this threat actor likely starts with spam bombing the victim’s inbox,” Zscaler says. “This assessment is based on similar campaigns that ThreatLabz has observed (such as Payouts King and other campaigns reported by Microsoft). These vishing attacks use Microsoft Teams, with the threat actor posing as IT/helpdesk staff offering assistance. The objective is to persuade the victim to open a Quick Assist link to establish a remote session.”
Once the attackers have remote access to the victim’s computer, they deploy several strains of malware to establish persistence and escalate privileges within the organization. After establishing a substantial foothold, the threat actor sells the access to ransomware gangs for follow-on attacks.
AI-native security awareness training can give your organization an essential layer of defense against social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce digital workforce risk.
Zscaler has the story: https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
