Since January 2026, this activity has been linked to an initial access broker that may sell or provide compromised environments to ransomware operators. The attackers impersonate IT or helpdesk personnel and contact victims via Microsoft Teams. In many cases, the social-engineering attempt follows spam bombing where a target receives a large volume of unwanted emails.

Once the victim opens a Microsoft Quick Assist session, the attackers use PowerShell to download malware, establish persistence, and begin reconnaissance. ThreatLabz discovered the Go-based backdoor family known as GoGRPC along with multiple reverse proxy tools that enable operators to access internal systems through compromised devices. This campaign showcases how legitimate remote-support software can serve as an entry point for long-term access, data theft, lateral movement, and potential ransomware deployment.

Function trees for GoGRPC backdoor variants (Source: Zscaler) Quick Assist Backdoor Hijack ThreatLabz identified four GoGRPC variants, named Lep, Giver, Pet, and Kind. These variants were first observed between January and June 2026, demonstrating a shift in design complexity with newer versions featuring enhanced obfuscation, stronger encryption support, and a greater focus on corporate targets.