Skip to main content
Mallory
MalwareUsed by 3 actorsExploits 4 CVEs

GOREshell

Also known asGOREVERSE

GoReShell is a Go-based backdoor/reverse shell malware cluster that includes the open-source reverse_ssh backdoor and custom variants such as GOREVERSE/Goreverse. It is described as a Windows backdoor in multiple reports, with additional reporting indicating variants were also deployed on Linux systems. The malware repurposes functionality from the open-source reverse_ssh tool to establish reverse SSH connections to attacker-controlled endpoints; some reporting also describes GOREVERSE as functioning as a reverse proxy server for post-exploitation access. Observed tradecraft includes use of SSH keys and WebSocket-based C2 communication, and samples have been noted as obfuscated with Garble and packed with UPX. The malware has been deployed in targeted intrusions and exploitation campaigns linked to China-nexus activity, including PurpleHaze and UNC5174, with overlaps to APT15 in some reporting. It has been observed in attacks against a South Asian government entity, a leading European media organization, and in broader campaigns affecting manufacturing, government, finance, telecommunications, and research sectors. Delivery and use contexts directly mentioned in the content include exploitation of Ivanti CSA vulnerabilities CVE-2024-8963 and CVE-2024-8190, SAP NetWeaver exploitation by UNC5174, and exploitation of GeoServer CVE-2024-36401 to deliver GOREVERSE. In those GeoServer cases, GOREVERSE was delivered via a script from hxxp://181[.]214[.]58[.]14:61231/remote.sh and connected to 181[.]214[.]58[.]14 on port 18201. The malware has also been associated with ORB (Operational Relay Box) infrastructure operated from China and with persistence/access-brokering activity alongside tools such as Snowlight, VShell, Neo-reGeorg, and suo5.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

4 CVES
CVE-2024-8190OS Command Injection RCE in Ivanti Cloud Services Appliance

"...drop a Go-based reverse shell dubbed GoReShell..." and "...deliver GOREVERSE, a variant of GoReShell."

via the hacker newsthehackernews.com
CVE-2024-8963Path Traversal in Ivanti Cloud Services Appliance

"...they deployed publicly available backdoors that belong to the GOREVERSE family, which Mandiant has linked to UNC5174."

via register securitygo.theregister.com
CVE-2025-31324Unauthenticated File Upload RCE in SAP NetWeaver Visual Composer Metadata Uploader

UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.

via security weeksecurityweek.com
CVE-2025-42999Insecure Deserialization in SAP NetWeaver Visual Composer Metadata Uploader

UNC5174 exploited vulnerable NetWeaver systems to deploy the Snowlight downloader, the VShell remote access trojan, and the SSH backdoor Goreverse.

via security weeksecurityweek.com
THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
PurpleHaze

...employing an operational relay box (ORB) network and a Windows backdoor dubbed GoReShell. The implant, written in the Go programming language, repurposes an open-source tool called reverse_ssh to set up reverse SSH connections...

via the hacker newsthehackernews.com
UNC5174

"...drop a Go-based reverse shell dubbed GoReShell..." and "...deliver GOREVERSE, a variant of GoReShell."

via the hacker newsthehackernews.com
Ke3chang

...employing an operational relay box (ORB) network and a Windows backdoor dubbed GoReShell.

via the hacker newsthehackernews.com
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities4

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.