Helpdesk Hijackers Turn Quick Assist Sessions Into Persistent Backdoor and Proxy Access

Active since January 202620262026, the activity appears linked to an initial access broker that may sell or provide compromised environments to ransomware operators.

The attackers impersonate IT or helpdesk personnel and contact victims through Microsoft Teams. In many cases, the social-engineering attempt is believed to follow spam bombing, where a target receives a large volume of unwanted emails.

The attackers then offer assistance and persuade the victim to open a Microsoft Quick Assist session.

Once the remote session is active, the attackers use PowerShell to download malware, establish persistence, and begin reconnaissance.

ThreatLabz identified a Go-based backdoor family named GoGRPC, along with multiple reverse proxy tools that allow operators to access internal systems through the compromised device.

The campaign demonstrates how legitimate remote-support software can become an entry point for long-term access, data theft, lateral movement, and possible ransomware deployment.

Function trees for GoGRPC backdoor variants (Source: zscaler)
Function trees for GoGRPC backdoor variants (Source: zscaler)

Quick Assist Backdoor Hijack

ThreatLabz identified four GoGRPC variants, named Lep, Giver, Pet, and Kind. The variants were first observed between January and June 202620262026.

While they share a similar design, newer versions show more obfuscation, stronger encryption support, and a clearer focus on corporate targets.

After execution, GoGRPC can create persistence through a Registry Run key, causing the malware to launch whenever the affected user signs in.

Earlier variants also created execution logs in the ProgramData directory, checked for existing malware instances through mutexes, and could hide files using Windows attributes.

The Lep and Giver variants collect system details including the Windows version, hostname, username, domain information, architecture, and machine GUID.

This information is used to create an identifier for the compromised endpoint. It is sent to the attackers’ command-and-control, or C2, infrastructure.

Communication protocol used byBlindDoor (Source: zscaler)
Communication protocol used byBlindDoor (Source: zscaler)

The Pet and Kind variants remove some fingerprinting functions but use heavier code obfuscation. They also add Transport Layer Security, or TLS, support for encrypted communications.

The Kind variant additionally obscures its gRPC protocol definition. It changes the C2 endpoint, making network detection and reverse engineering more difficult.

GoGRPC uses gRPC over HTTP/2 for C2 communications, an uncommon choice for a malware backdoor. Because gRPC traffic can resemble legitimate modern web application traffic, it may help attackers reduce suspicion in enterprise networks.

Earlier versions used port 443443443 without TLS, while the newer Pet and Kind versions added encryption, Zscaler said.

Indicators of Compromise

Indicator TypeIndicatorDescription
SHA-25666b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5Giver GoGRPC backdoor
SHA-2569136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52Lep GoGRPC backdoor

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories