Skip to main content
Mallory
MalwareRansomwareUsed by 2 actors

GotoHTTP

GotoHTTP is a cross-platform remote access and remote monitoring/management (RMM) tool used by threat actors to obtain persistent remote control of compromised systems. Reported capabilities include establishing persistence, file transfer, and screen viewing, and it is described as using a browser-to-client architecture over common ports 80/443. In the provided reporting, GotoHTTP was repeatedly deployed post-compromise via web shells, PowerShell, and VBScript. Cisco Talos reported UAT-8099 using web shells and PowerShell on vulnerable Microsoft IIS servers across Asia, especially in Thailand and Vietnam, to download and execute GotoHTTP, save it as "xixixi.exe," and exfiltrate the generated "gotohttp.ini" configuration file to a C2 server so the actor could recover the connection ID and password needed to control the infected server. Talos also noted GotoHTTP was used for persistence and to support delivery of updated BadIIS malware variants in an SEO-fraud campaign overlapping with WEBJACK. Elastic and TAMUS separately observed a Chinese-speaking intrusion cluster tracked as REF3927 upload and execute the legitimate GotoHTTP RMM tool on compromised Windows IIS/ASP.NET servers to maintain access after ViewState-based exploitation. SentinelLABS also reported DragonSpark, assessed as a Chinese-speaking actor targeting organizations in East Asia, using GotoHTTP alongside other Chinese-developed tooling. In ransomware-related reporting, investigators found GotoHTTP on victim machines the day after Reynolds ransomware deployment, and multiple reports state attackers deployed it after encryption to maintain persistent access for further exploitation or negotiation. High-confidence artifacts directly mentioned include the filename "xixixi.exe" and the configuration file "gotohttp.ini".

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
REF3927

...execute GotoHTTP remote access tool...

via the hacker newsthehackernews.com
DragonSpark

GotoHTTP: a cross-platform remote access tool that implements a wide array of features, such as establishing persistence, file transfer, and screen view.

via sentinelone labssentinelone.com
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Collection

1 technique
T1113Screen CaptureEvidence1

“Information theft… screenshot theft” / “screen view”

T1105Ingress Tool TransferEvidence1

“deployment of malware and tools hosted at attacker-controlled infrastructure.” / staging URLs for py.exe, m6699.exe, c.exe, go.exe

INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app3 years ago
uri●●●●●●●●●●●●View more in app3 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.