Skip to main content
Mallory
MalwareUsed by 1 actor

GoExec

GoExec is a Golang-based remote execution tool used to execute commands on other connected remote endpoints within a victim network, including via WMI and DCOM. Cisco Talos reported its use by the threat actor UAT-8837, which Talos assesses with medium confidence to be a China-nexus actor focused on obtaining initial access to high-value organizations and targeting critical infrastructure sectors in North America since at least 2025. In UAT-8837 intrusions, GoExec was part of a broader post-compromise toolset used after access was gained through exploitation of vulnerable servers or compromised credentials, including exploitation of Sitecore CVE-2025-53690. Talos reported that UAT-8837 used Impacket, Invoke-WMIExec, GoExec, and SharpWMI interchangeably for remote command execution and cycled through these tools when detection blocked execution. The surrounding activity included reconnaissance, credential and Active Directory information collection, disabling RDP RestrictedAdmin, and hands-on-keyboard post-exploitation. No standalone infection vector or malware-specific indicators of compromise for GoExec were provided in the content beyond its observed operational use as a remote execution utility.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UAT-8837

GoExec, a Golang-based tool to execute commands on other connected remote endpoints within the victim's network

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1059Command and Scripting InterpreterEvidence1
TacticExecution

Impacket, to run commands with elevated privileges ... GoExec, a Golang-based tool to execute commands on other connected remote endpoints within the victim's network

Discovery

1 technique
T1082System Information DiscoveryEvidence1
TacticDiscovery

UAT-8837 may run a series of commands during the intrusion to obtain sensitive information, such as credentials from victim organizations

Lateral Movement

1 technique
T1021Remote ServicesEvidence2

“GoExec, a remote execution tool, was described as ‘likely an on-the-fly decision by the operator’...”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.