{
  "Name": "GoToMyPC",
  "Category": "RMM",
  "Description": "GoToMyPC is a remote monitoring and management (RMM) tool. More information will be added as it becomes available.\n",
  "Author": "Nasreddine Bencherchali",
  "Created": "2024-08-05",
  "LastModified": "2024-08-05",
  "Details": {
    "Website": "https://get.gotomypc.com/",
    "PEMetadata": [
      {
        "Filename": "AppCore.exe"
      },
      {
        "Filename": "g2comm.exe"
      },
      {
        "Filename": "g2file*.exe"
      },
      {
        "Filename": "g2fileh.exe"
      },
      {
        "Filename": "g2host.exe"
      },
      {
        "Filename": "g2m_download.exe"
      },
      {
        "Filename": "g2mainh.exe"
      },
      {
        "Filename": "G2MChat.exe"
      },
      {
        "Filename": "G2M.exe"
      },
      {
        "Filename": "G2MCodecInstExtractor.exe"
      },
      {
        "Filename": "G2MComm.exe"
      },
      {
        "Filename": "G2MCoreInstExtractor.exe"
      },
      {
        "Filename": "G2MFeedback.exe"
      },
      {
        "Filename": "G2MHost.exee"
      },
      {
        "Filename": "G2MInstaller.exe"
      },
      {
        "Filename": "G2MInstallerExtractor.exe"
      },
      {
        "Filename": "G2MInstHigh.exe"
      },
      {
        "Filename": "G2MLauncher.exe"
      },
      {
        "Filename": "G2MMatchMaking.exe"
      },
      {
        "Filename": "G2MMaterials.exe"
      },
      {
        "Filename": "G2MPolling.exe"
      },
      {
        "Filename": "G2MQandA.exe"
      },
      {
        "Filename": "G2MRecorder.exe"
      },
      {
        "Filename": "G2MScrUtil64.exe"
      },
      {
        "Filename": "G2MSessionControl.exe"
      },
      {
        "Filename": "G2MStart.exe"
      },
      {
        "Filename": "G2MTesting.exe"
      },
      {
        "Filename": "G2MTranscoder.exe"
      },
      {
        "Filename": "G2MUI.exe"
      },
      {
        "Filename": "G2MUninstall.exe"
      },
      {
        "Filename": "g2mupload.exe"
      },
      {
        "Filename": "g2mvideoconference.exe"
      },
      {
        "Filename": "G2MView.exe"
      },
      {
        "Filename": "g2printh.exe"
      },
      {
        "Filename": "g2quick.exe"
      },
      {
        "Filename": "g2svc.exe"
      },
      {
        "Filename": "g2tray.exe"
      },
      {
        "Filename": "gopcsrv.exe"
      },
      {
        "Filename": "GoToScrUtils.exe"
      },
      {
        "Filename": "GoTo.exe",
        "OriginalFileName": "",
        "Description": ""
      }
    ],
    "Privileges": "",
    "Free": "",
    "Verification": "",
    "SupportedOS": [],
    "Capabilities": [],
    "Vulnerabilities": [],
    "InstallationPaths": [
      "C:\\Program Files (x86)\\GoToMyPC\\*",
      "G2M.exe",
      "%APPDATA%\\GoToMeeting\\G2M.exe"
    ]
  },
  "Artifacts": {
    "Disk": [
      {
        "File": "%AppData%\\GoTo\\Logs\\goto.log",
        "Description": "N/A",
        "OS": "Windows"
      },
      {
        "File": "%APPDATA%\\GoToMeeting\\G2M.exe",
        "Description": "Legitimate, LogMeIn-signed GoToMeeting binary observed in the wild as a DLL-search-order-hijacking host. The Zscaler OpenClaw campaign (May 2025) shipped G2M.exe inside a malicious MSI alongside a malicious `g2m.dll` placed in the same directory so the signed binary loaded the attacker DLL on launch, then decrypted Remcos RAT shellcode. Hunt for `G2M.exe` running with a non-LogMeIn-signed `g2m.dll` next to it.",
        "OS": "Windows"
      }
    ],
    "EventLog": [],
    "Registry": [
      {
        "Path": "HKEY_LOCAL_MACHINE\\WOW6432Node\\Citrix\\GoToMyPc",
        "Description": "Configuration settings including registration email"
      },
      {
        "Path": "HKEY_LOCAL_MACHINE\\WOW6432Node\\Citrix\\GoToMyPc\\GuestInvite",
        "Description": "Guest invites send to connect"
      },
      {
        "Path": "HKEY_CURRENT_USER\\SOFTWARE\\Citrix\\GoToMyPc\\FileTransfer\\history",
        "Description": "hostname of the computer making connections and location of transferred files"
      },
      {
        "Path": "HKEY_USERS\\<SID>\\SOFTWARE\\Citrix\\GoToMyPc\\FileTransfer\\history",
        "Description": "hostname of the computer making connections and location of transferred files"
      }
    ],
    "Network": [
      {
        "Description": "N/A",
        "Domains": [
          "*.GoToMyPC.com"
        ],
        "Ports": []
      }
    ]
  },
  "Detections": [
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/gotomypc_registry_sigma.yml",
      "Description": "Detects potential registry activity of GoToMyPC RMM tool"
    },
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/gotomypc_network_sigma.yml",
      "Description": "Detects potential network activity of GoToMyPC RMM tool"
    },
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/gotomypc_files_sigma.yml",
      "Description": "Detects potential files activity of GoToMyPC RMM tool"
    }
  ],
  "References": [
    "https://support.logmeininc.com/gotomypc/help/what-are-the-optimal-firewall-configurations#",
    "https://support.goto.com/training/help/how-do-i-configure-gototraining-to-work-with-firewalls",
    "https://ruler-project.github.io/ruler-project/RULER/remote/Citrix%20GoToMyPC/",
    "https://www.zscaler.com/blogs/security-research/malicious-openclaw-skill-distributes-remcos-rat-and-ghostloader",
    "https://www.virustotal.com/gui/file/0d3ca4872e757fa406c10aa6893e831c2aaadce0687537d14fdce1702517b2d0/behavior"
  ],
  "Acknowledgement": [
    {
      "Person": "Phill Moore",
      "Handle": "@phillmoore"
    },
    {
      "Person": "Daniel Koifman",
      "Handle": "@KoifSec"
    }
  ]
}