Go2Tunnel is a Go-based SSH reverse-tunneling utility used by the threat cluster tracked as Armored Likho, also known as Eagle Werewolf, to provide covert remote access into compromised Windows systems. It is designed to expose a victim host’s local SSH service to attacker-controlled infrastructure by launching SSH with reverse port forwarding and maintaining tunnel availability over time. The tool has been observed as part of multi-stage intrusion chains involving phishing-delivered droppers and follow-on remote access tooling.
Operationally, Go2Tunnel reads tunnel parameters from local configuration data and can either use a predefined remote tunnel port or request one dynamically from a remote web service. It then starts an SSH reverse tunnel that forwards an externally reachable port on the attacker side to the victim’s local SSH endpoint. The utility also monitors tunnel health and, if connectivity fails, terminates and recreates the SSH process to restore access. In observed campaigns, surrounding scripts configured SSH services, deployed keys, and prepared the host for persistent remote administration.
Go2Tunnel has been associated with Eagle Werewolf operations targeting government, industrial, and UAV-related victims, and with later Armored Likho activity against government agencies and the electric power sector in Russia, Kazakhstan, and Brazil. In earlier campaigns it functioned as a standalone tunneling component alongside Rust and Go droppers and AquilaRAT. Later operations incorporated equivalent reverse SSH tunneling functionality directly into BusySnake Stealer, indicating that Go2Tunnel’s role was to furnish persistent remote access and interactive control rather than data theft itself.
The malware has been delivered in phishing and lure-driven campaigns, including archives containing disguised executables and Telegram-distributed lures in some Eagle Werewolf activity. Its use is consistent with post-compromise access enablement, persistence support, and network tunneling on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Réutilisation de la fonctionnalité de tunnel SSH inversé (précédemment dans Go2Tunnel )
Réutilisation de la fonctionnalité de tunnel SSH inversé (précédemment dans Go2Tunnel )
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Subsequently, it attempts to add the new account to the Administrators group.
Большинство файлов — это полный набор для настройки SSH-соединения, публичные и приватные ключи и конфиги. Скрипты... запускают SSHD и ssh-agent, настроив публичный и приватный ключ.
Subsequently, it attempts to add the new account to the Administrators group.
Set-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" -Name $sshUserName -Value 0 -Type DWord
Subsequently, it attempts to add the new account to the Administrators group.
They utilize Go2Tunnel alongside obfuscated, modular RATs and infostealers engineered to bypass dynamic analysis.
The dropper contains the EchoGather payload, which is Base64-encoded and XOR-encrypted.
В архиве с громким названием 1С_модуль_заказа_дрон-v11.zip лежит файлик СВЯЗЬ РЭБ список Гум.exe со знакомым всем желтым значком «1С». При запуске файла пользователь видит стандартное окно загрузки «1C:Enterprise 8.3» с последующим открытием базы данных.
At the final stage of execution, the Rust dropper deletes the insider-[a-zA-Z0-9]{6} directory.
Impact & Control: This diverse stack enables them to maintain stealthy host control, exfiltrate credentials, and deploy tailored modules.
В случае когда serverTunnelPort не указан, выполняется POST-запрос по следующему адресу: http://<serverHostname>:<ServerWebPort>/tunnel/register
Also put to use in the attacks is Go2Tunnel to establish a reverse SSH tunnel to a command-and-control (C2) server using a private key.
handle_start_proxy_command / handle_stop_proxy_command Establishes a reverse SSH tunnel using an SSH command and private key previously received from the C2 server.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a related tool previously used for reverse SSH tunneling functionality that appears reused in the BusySnake campaign.
Tool used by Armored Likho for remote access and network tunneling, specifically to establish a reverse SSH tunnel before that functionality was folded into BusySnake Stealer.
A malware/tool in the actor toolkit used alongside BusySnake and other modular RATs/infostealers to support stealthy host control and campaign operations.
A tool used by the threat actor for remote access and reverse SSH tunneling to C2 infrastructure. The article says its reverse-tunneling functionality was previously standalone and has now been integrated directly into BusySnake.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.