GoThief is a Go-based infostealer observed in attacks exploiting CVE-2024-23692 in Rejetto/HTTP File Server (HFS), including HFS 2.3m and 2.4.0 RC7. AhnLab Security Intelligence Center (ASEC) reported it being deployed on compromised HFS servers alongside RATs such as Gh0stRAT, PlugX, and XenoRAT. The malware is described as stealing information via Amazon AWS, specifically using Amazon S3 bucket "imgdev" to upload collected data. Reported collection behavior includes capturing screenshots, gathering desktop file information, and collecting IP address information before forwarding data to another command-and-control server. AhnLab states the malware was classified as GoThief based on the source code path string "E:/Thief/GoThief-main/main.go" found in a sample. High-confidence indicators mentioned in the content include MD5 hash 4383b1ea54a59d27e5e6b3122b3dadb2, C2 endpoint 188.116.22[.]65:5000/submit, and download URL imgdev.s3.eu-west-3.amazonaws[.]com/dev/20210623/conost.exe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“A major example is GoThief which uses Amazon AWS to steal information from the infected system.”
3 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based infostealer that captures screenshots and enumerates desktop files, uploads data to an Amazon S3 bucket (imgdev), and forwards collected information (including IP info) to a separate C2 endpoint.
Data-stealing malware reported to exfiltrate sensitive data via Amazon AWS, observed being deployed against Rejetto HFS servers following exploitation activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.