Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infection

https://hackread.com/wp-content/uploads/2026/07/fake-it-calls-microsoft-teams-gogrpc-backdoor.jpg

A Microsoft Teams call from someone posing as company IT support can lead an employee to approve a Quick Assist session, giving the attacker remote control of the computer.

Zscaler ThreatLabz has tracked these voice-phishing attacks, commonly called vishing, since January 2026 in which, after gaining access, the attackers use PowerShell to inspect the system to install a new backdoor named GoGRPC

Once the employee approves the Quick Assist session, the attacker can view and control the computer. They then use PowerShell commands to collect information about the device, download malware and configure it to start whenever the user signs in.

Antivirus& Malware

The company believes that some attacks may also begin with an email flood that fills the victim’s inbox with unwanted messages. The fake support workerthen calls through Teams and offers to solve the apparent email problem. Researchers based this part of their assessment on similar...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more