GoReShell, also referred to as GOREVERSE, is a Go-based backdoor used to establish reverse SSH connectivity from compromised systems to attacker-controlled infrastructure. It is derived from or repurposes functionality from the open-source reverse_ssh tool and has been used as a post-exploitation implant to provide persistent remote access, reverse shell capability, and proxy-style tunneling for follow-on operations. Reported variants have been observed on both Windows and Linux, including ELF samples on Unix-like systems and Windows backdoor deployments in espionage intrusions.
The malware has been associated with China-nexus intrusion activity, particularly clusters linked to UNC5174 and PurpleHaze, and has also been referenced in activity overlapping with Houken. It has been deployed after exploitation of internet-facing enterprise software and edge devices, including Ivanti Cloud Services Appliance, SAP NetWeaver, and GeoServer. In these campaigns, GoReShell commonly appears after initial compromise to maintain access, support operator command execution, and enable further internal operations. It has also been observed alongside webshells, proxy tools, reconnaissance utilities, and other malware families used in broader intrusion chains.
Operational use of GoReShell is consistent with cyberespionage and access-enablement objectives. Victim sectors linked to campaigns using this malware include government, media, telecommunications, finance, transport, research, and technology, with activity spanning Europe, South Asia, and other regions. Some reporting also describes its use as part of access-brokering or foothold-establishment operations, where durable remote access to compromised environments is a primary goal.
Observed variants have used obfuscation and packing techniques, including Garble and UPX, to hinder analysis and detection. In addition to reverse shell functionality, GoReShell has been described as supporting reverse proxy behavior and outbound SSH-based tunnels that facilitate post-exploitation activity and persistence on compromised hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On April 24, 2025, SAP disclosed CVE-2025-31324, a critical vulnerability with a CVSS score of 10.0 affecting the SAP NetWeaver's Visual Composer Framework, version 7.50. This vulnerability allows unauthenticated users to upload arbitrary files to an SAP NetWeaver application server, leading to potential remote code execution (RCE) and full system compromise. | We have also observed attackers deploying other reverse shell tools with the filename config. These include a publicly available tool that Google calls GOREVERSE.
"...drop a Go-based reverse shell dubbed GoReShell..." and "...deliver GOREVERSE, a variant of GoReShell."
"...they deployed publicly available backdoors that belong to the GOREVERSE family, which Mandiant has linked to UNC5174."
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Houken operators notably deployed the following GOREVERSE payloads... GOREVERSE is the name given by Google Threat Intelligence Group to a reverse shell backdoor written in GoLang.
In April 2025, SentinelOne disclosed details of a threat cluster dubbed PurpleHaze that targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts.
...employing an operational relay box (ORB) network and a Windows backdoor dubbed GoReShell.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
PurpleHaze activity cluster leveraged the GOREshell backdoor and an Operational Relay Box (ORB) network
We observed attackers deploying other reverse shell tools... GOREVERSE has the following capabilities: ... Dynamic, local and remote forwarding ... Multiple network transports... We observed an attacker execute ... a Base64-encoded PowerShell script... Uses ssh.exe to establish a remote tunnel to the C2 server.
In this instance, the threat actor first downloaded a shell script config.sh to the compromised SAP server using the initial helper.jsp webshell... We observed an attacker execute the following PowerShell command to download a suspicious payload...
To ensure persistence after lateral movements, Houken operators notably deployed the following GOREVERSE payloads... The following public tools were observed on the victims’ network... Backdoors and other persistence mechanisms: – GOREVERSE (reverse_ssh); – ReverseSSH; – SparkRAT;
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows backdoor that uses reverse_ssh functionality to establish reverse SSH connections to attacker-controlled hosts.
GOREVERSE is a backdoor malware that allows remote access and control of compromised systems. It was distributed via exploitation of the GeoServer vulnerability.
GOREVERSE is a reverse shell tool used by attackers to maintain persistent remote access to compromised systems.
GOREVERSE is a backdoor malware, a variant of GoReShell, used to maintain persistence and enable remote access on compromised systems. It is deployed after initial exploitation and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.