GoReShell is a Go-based reverse-shell backdoor family that repurposes functionality from the open-source reverse_ssh tool. It establishes outbound SSH connections to attacker-controlled infrastructure, enabling remote shell access and tunneling for post-exploitation operations and continued access to compromised systems. Related variants are tracked as GOREVERSE and can function as reverse proxies. Windows and Linux variants have been observed, including deployments on compromised Ivanti appliances. Some samples use Garble obfuscation or UPX packing to hinder analysis.
GoReShell has been deployed in China-nexus cyberespionage activity tracked as PurpleHaze, including intrusions involving a South Asian government-supporting entity and a European media organization. These operations used Operational Relay Box networks to obscure attacker infrastructure. GOREVERSE-family payloads have also been associated with UNC5174 and Houken operations. Deployment has followed exploitation of internet-facing enterprise applications and appliances, including Ivanti CSA vulnerabilities CVE-2024-8963 and CVE-2024-8190, GeoServer vulnerability CVE-2024-36401, and SAP NetWeaver vulnerability CVE-2025-31324. The family provides a remote-access foothold within broader intrusion chains; credential theft, rootkit installation, and cryptocurrency mining observed in those campaigns are not established capabilities of GoReShell itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
GeoServer의 원격 코드 실행 취약점(CVE-2024-36401)이 공개된 이후 최근까지도 해당 취약점을 악용해 악성코드를 설치하는 사례들이 확인되고 있다.
On April 24, 2025, SAP disclosed CVE-2025-31324, a critical vulnerability with a CVSS score of 10.0 affecting the SAP NetWeaver's Visual Composer Framework, version 7.50. This vulnerability allows unauthenticated users to upload arbitrary files to an SAP NetWeaver application server, leading to potential remote code execution (RCE) and full system compromise. | We have also observed attackers deploying other reverse shell tools with the filename config. These include a publicly available tool that Google calls GOREVERSE.
"...drop a Go-based reverse shell dubbed GoReShell..." and "...deliver GOREVERSE, a variant of GoReShell."
"...they deployed publicly available backdoors that belong to the GOREVERSE family, which Mandiant has linked to UNC5174."
UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Houken operators notably deployed the following GOREVERSE payloads... GOREVERSE is the name given by Google Threat Intelligence Group to a reverse shell backdoor written in GoLang.
In April 2025, SentinelOne disclosed details of a threat cluster dubbed PurpleHaze that targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts.
...employing an operational relay box (ORB) network and a Windows backdoor dubbed GoReShell.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
PurpleHaze activity cluster leveraged the GOREshell backdoor and an Operational Relay Box (ORB) network
We observed attackers deploying other reverse shell tools... GOREVERSE has the following capabilities: ... Dynamic, local and remote forwarding ... Multiple network transports... We observed an attacker execute ... a Base64-encoded PowerShell script... Uses ssh.exe to establish a remote tunnel to the C2 server.
In this instance, the threat actor first downloaded a shell script config.sh to the compromised SAP server using the initial helper.jsp webshell... We observed an attacker execute the following PowerShell command to download a suspicious payload...
To ensure persistence after lateral movements, Houken operators notably deployed the following GOREVERSE payloads... The following public tools were observed on the victims’ network... Backdoors and other persistence mechanisms: – GOREVERSE (reverse_ssh); – ReverseSSH; – SparkRAT;
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows backdoor that uses reverse_ssh functionality to establish reverse SSH connections to attacker-controlled hosts.
GOREVERSE is a backdoor malware that allows remote access and control of compromised systems. It was distributed via exploitation of the GeoServer vulnerability.
Named as a payload distributed through exploitation of the GeoServer vulnerability in previously reported attacks. This article provides no further details about its capabilities.
GOREVERSE is a reverse shell tool used by attackers to maintain persistent remote access to compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.