GotoHTTP is a cross-platform remote access and remote monitoring tool used by multiple threat actors as post-compromise accessware on Windows, Linux, and server environments including Microsoft IIS infrastructure. It provides remote control capabilities such as persistence, command execution, file transfer, and screen viewing, and has been observed deployed both directly and through in-memory loaders or encrypted payload chains to reduce detection. In intrusion activity, operators have used GotoHTTP to maintain access before and after other objectives such as cryptomining, SEO fraud, and ransomware deployment.
GotoHTTP has been associated with several distinct intrusion clusters. In compromises attributed to Larva-26009 targeting MS-SQL and IIS servers, it was installed alongside other remote administration and tunneling tools to control infected systems, sometimes executed from decrypted shellcode loaders and used in conjunction with web shells, privilege-escalation tooling, internal scanning, and hidden-account persistence. In DragonSpark activity, a Chinese-speaking threat actor used GotoHTTP as one of several open-source tools during opportunistic attacks against exposed web and database servers. In campaigns tracked as UAT-8099 against vulnerable IIS servers in Asia, attackers used web shells and PowerShell or VBScript to download and launch GotoHTTP, then exfiltrated its configuration to obtain the credentials needed for continued remote administration; this activity supported persistent access and follow-on deployment of BadIIS variants used for SEO fraud. In separate ransomware-related intrusions, GotoHTTP was found on victim systems after encryption, indicating likely post-encryption persistence and continued operator access.
The tool is legitimate in origin but is repeatedly abused as an access mechanism in hands-on-keyboard intrusions. Its observed role is primarily persistent remote administration after initial compromise rather than initial delivery itself, and it commonly appears alongside web shells, loaders, tunneling utilities, and other post-exploitation tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...in this particular attack case, the attacker installed VShell and GotoHTTP to gain control over the [...]
GotoHTTP: a cross-platform remote access tool that implements a wide array of features, such as establishing persistence, file transfer, and screen view.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actor used GotoHTTP to install privilege escalation tools and executed commands as follows: > Net group /domain
While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner.
used certutil.Exe to decrypt the web shell downloaded from the internet.
VShell is a backdoor malware developed in the Go programming language... supports protocols such as TCP, HTTP, and UDP for communication with the C&C server
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access/control tool used by the attacker to manage the compromised MS-SQL server.
A remote control tool used by the threat actor for system control and command execution, including running privilege escalation tools on compromised hosts.
Remote access tool observed post-compromise, likely used to maintain access before/after ransomware deployment.
Remote access tool deployed post-encryption in some Reynolds incidents to maintain persistence and enable follow-on activity (e.g., further exploitation, negotiation, potential data access/exfiltration).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.