GOST (Go Simple Tunnel) is an open-source proxy and tunneling tool written in Go. It is legitimate dual-use software rather than an intrinsically malicious malware family, but attackers deploy it after compromise to establish SOCKS5 proxies, reverse TCP tunnels, and communication channels into victim networks. These deployments expose internal services, support network pivoting, and maintain external access to compromised systems.
Malicious use has been documented on Windows systems, Linux servers, Palo Alto Networks firewalls, and cloud-hosted container environments. Akira ransomware affiliates have used GOST tunnels to retain access to compromised organizations. UTA0218 deployed GOST on firewalls compromised through CVE-2024-3400, establishing SOCKS5 and reverse TCP tunnels through an SSH connection. The China-aligned espionage cluster SHADOW-EARTH-053 has included GOST among its tunneling tools in operations targeting government, defense-adjacent, transportation, technology, and critical infrastructure organizations. TeamPCP and PCPcat operations have installed GOST alongside FRP to maintain access to compromised servers and container environments.
Attackers have maintained GOST deployments through persistent systemd services. Windows deployments have also used legitimate-looking software identities and altered executable timestamps to conceal the tool. These behaviors reflect attacker deployment practices, not evidence that GOST itself performs credential theft, ransomware encryption, or initial exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This version attempts to download a Golang tunneling tool named GOST and execute it with two different command-line options to establish SOCKS5 and RTCP tunnels.
Observed tooling included IOX Proxy, GOST, Wstunnel, and multiple tunnel-core.exe variants. These tools established SOCKS5 proxies, HTTPS tunnels, and reverse communication channels to attacker infrastructure.
Tunneling tools: TeamPCP uses frps (fast reverse proxy) and gost for establishing persistent tunnels and proxying through compromised container environments
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Tunneling tools: TeamPCP uses frps (fast reverse proxy) and gost for establishing persistent tunnels and proxying through compromised container environments
Upon launch, it connected to the C2 server, allowing the operator to execute commands on the compromised host... Cloudflared tunnels traffic through the Cloudflare network.
Mandiant observed UNC5330 operating a server since Dec. 6, 2021, which the group used as a GOST proxy to help facilitate malicious tool deployment to endpoints.
The group uses reverse SSH tunnels with -R port forwarding and tools including GOST, rsocx, cloudflared, and localtonet to redirect traffic.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate open-source tunnelling software abused to maintain access after the ransomware attack. Its binary masqueraded as svchost.exe, ran as SYSTEM from C:\PerfLogs\Temp\, loaded config.dll, and communicated with 64.227.4[.]134. The tunnel was established approximately four hours after encryption began.
Proxy tool deployed in VMware Tools and WSUS locations while masquerading as legitimate components. The VMware-themed executable had altered timestamps, and the WSUS-themed executable was deleted before examination. A GOST proxy configuration was recovered from command-and-control exchanges.
A tunneling/proxy framework used for covert communications and persistence inside victim networks.
Used by TeamPCP to establish persistent tunnels and proxy traffic through compromised container environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.