Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareUsed by 2 actors

GO Simple Tunnel

GOST (GO Simple Tunnel) is a network tunneling and proxy utility used to forward traffic across networks and enable pivoting, reverse proxying, and command-and-control tunneling. Reporting in the provided content shows it being used by multiple threat actors and operations as a post-compromise access and lateral movement enabler rather than as a bespoke malware family. In a Blackpoint SOC investigation of an MSP intrusion, the threat actor deployed GOST in downstream customer environments after abusing NinjaOne access; it was installed as malicious Windows services via sc.exe create, masquerading as legitimate components and pointing to a fake svchost.exe under C:\Windows\System32*\svchost.exe. Those services established a local SOCKS listener and a reverse TCP relay for durable pivoting. Blackpoint also reported actor-linked exposed Apache directories containing staged GOST executables. Related IOCs from that case included temp[.]sh, IPs 149.28.244[.]152, 45.76.233[.]211, 149.28.253[.]247, 216.128.134[.]133, 45.63.39[.]209, 194.87.125[.]253, 142.248.80[.]106, and 104.238.29[.]81, and a fake svchost.exe SHA-256 of 32ade1df0b89c5922fbb8a1e11a581e887d95db184fe51e02c68c02c2cb63efa. The content also states that during Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool, and that Ember Bear used socket-based tunneling utilities such as NetCat and GOST for command and control. Unit 42 reporting on the Shadow Campaigns attributed to TGR-STA-1030/UNC6619 describes GOST as one of the tunneling tools used alongside FRPS and IOX in a large cyberespionage campaign targeting at least 70 government and critical infrastructure organizations across 37 countries, with victims spanning ministries of finance, law enforcement, border control, energy, telecommunications, mining, trade, and national parliaments.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Ember Bear

Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST).

via mitre attackattack.mitre.org
TGR-STA-1030

"...network tunneling tools such as GO Simple Tunnel (GOST), Fast Reverse Proxy Server (FRPS), and IOX."

via bleeping computerbleepingcomputer.com
INDICATORS OF COMPROMISE

IOCs tracked for this family

9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
8 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app10 days ago
ip.v4●●●●●●●●●●●●View more in app3 months ago
hash.sha256●●●●●●●●●●●●View more in app3 months ago
ip.v4●●●●●●●●●●●●View more in app3 months ago
ip.v4●●●●●●●●●●●●View more in app3 months ago
ip.v4●●●●●●●●●●●●View more in app3 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching9

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.