GoToHTTP

Malware type
rat
Profile updated
2026-07-07 13:16:57

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

According to ESET Research, GoToHTTP is a benign tool that allows establishing a remote connection that can be accessed from a browser. It has been observed being abused for malicious purposes by threat actor GhostRedirector.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Gotohttp_Auto (yara-rule)

Reports & references

  • ESET — Ghostredirector Poisons Windows Servers Backdoors Side Potatoes (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Gotohttp (report)

External references