Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The second is more recent and involved the successful exploitation of CVE-2022-1040, a remote code execution vulnerability in Sophos Firewall. | Cisco Talos confirmed that the malware is a slightly modified version of the open-source backdoor named "GoMet."
First, in 2020, attackers were deploying this malware after the successful exploitation of CVE-2020-5902, a vulnerability in F5 BIG-IP so severe that USCYBERCOM posted a tweet urging all users to patch the application. | Cisco Talos confirmed that the malware is a slightly modified version of the open-source backdoor named "GoMet."
Deployment of Remote Access Toolkits (RATs) – we observed various RATs including PupyRAT and GoMet
Deployment of Remote Access Toolkits (RATs) – we observed various RATs including PupyRAT and GoMet
Deployment of Remote Access Toolkits (RATs) – we observed various RATs including PupyRAT and GoMet
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious activity we detected included a fake Windows update scheduled tasks created by the GoMet dropper.
The malicious activity we detected included a fake Windows update scheduled tasks created by the GoMet dropper.
The malicious activity we detected included a fake Windows update scheduled tasks created by the GoMet dropper.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source Go-based backdoor that supports job scheduling, single-command execution, file download/upload, shell access, and daisy-chaining between infected hosts for pivoting and communication from isolated systems. In this campaign, attackers used a modified version with more aggressive reconnection behavior and persistence via scheduled tasks and replacement of existing autorun executables.
Backdoor/RAT referenced as being deployed by attackers following exploitation activity in the honeypot dataset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.