HEURRemoteAdmin.GoToResolve.gen is a detection name for a potentially unwanted application (PUA) associated with the legitimate GoTo Resolve remote support product (formerly LogMeIn). According to Point Wild’s Lat61 Threat Intelligence Team, unauthorized instances can install silently, persist on a system, hide under "C:\Program Files (x86)\GoTo Resolve Unattended", and run in the background without user interaction. Researchers also identified an installer-bundled file named "32000~" containing instructions for managing the application. The primary concern is that, although the software is part of a legitimate remote administration platform and may be digitally signed by GoTo Technologies USA, LLC, it can be hijacked and abused by attackers as a stealthy gateway for unauthorized access. Reported behavior includes loading the Windows Restart Manager library (RstrtMgr.dll), which Point Wild notes has previously been used by Conti ransomware, Cactus ransomware, and the BiBi wiper to terminate interfering processes. This capability could allow attackers to disable antivirus or other security tools, support anti-analysis, and pre-position a host for follow-on destructive activity. Point Wild recommends treating any unauthorized instance as high risk and removing it unless explicitly approved by the organization’s security team.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A silently installed/operated remote administration component associated with GoTo Resolve that can be abused/hijacked for unauthorized access and persistence; noted for stealthy background execution and use of Windows Restart Manager (RstrtMgr.dll) to help terminate security processes.
Detection name for GoTo Resolve remote administration software being flagged as a potentially unwanted application due to silent installation/persistence and potential misuse as an attacker-controlled remote access gateway; noted as capable of loading Windows Restart Manager (RstrtMgr.dll), which can be abused to terminate security/locking processes and facilitate follow-on attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.