RMM

GoToMyPC

GoToMyPC is a remote monitoring and management (RMM) tool. More information will be added as it becomes available.

Tool overview

Category
RMM
Research authors
Nasreddine Bencherchali
Created
2024-08-05
Last modified
2024-08-05
Privileges
Not recorded
Free / availability
Not recorded
Verification required
Not recorded
Supported platforms
Not recorded

Executables & installation paths

Filename
AppCore.exe
Filename
g2comm.exe
Filename
g2file*.exe
Filename
g2fileh.exe
Filename
g2host.exe
Filename
g2m_download.exe
Filename
g2mainh.exe
Filename
G2MChat.exe
Filename
G2M.exe
Filename
G2MCodecInstExtractor.exe
Filename
G2MComm.exe
Filename
G2MCoreInstExtractor.exe
Filename
G2MFeedback.exe
Filename
G2MHost.exee
Filename
G2MInstaller.exe
Filename
G2MInstallerExtractor.exe
Filename
G2MInstHigh.exe
Filename
G2MLauncher.exe
Filename
G2MMatchMaking.exe
Filename
G2MMaterials.exe
Filename
G2MPolling.exe
Filename
G2MQandA.exe
Filename
G2MRecorder.exe
Filename
G2MScrUtil64.exe
Filename
G2MSessionControl.exe
Filename
G2MStart.exe
Filename
G2MTesting.exe
Filename
G2MTranscoder.exe
Filename
G2MUI.exe
Filename
G2MUninstall.exe
Filename
g2mupload.exe
Filename
g2mvideoconference.exe
Filename
G2MView.exe
Filename
g2printh.exe
Filename
g2quick.exe
Filename
g2svc.exe
Filename
g2tray.exe
Filename
gopcsrv.exe
Filename
GoToScrUtils.exe
Filename
GoTo.exe
OriginalFileName
Not recorded
Description
Not recorded

Installation paths

C:\Program Files (x86)\GoToMyPC\*
G2M.exe
%APPDATA%\GoToMeeting\G2M.exe

FORENSIC EVIDENCE

Disk artifacts

File
%AppData%\GoTo\Logs\goto.log
Description
N/A
OS
Windows
File
%APPDATA%\GoToMeeting\G2M.exe
Description
Legitimate, LogMeIn-signed GoToMeeting binary observed in the wild as a DLL-search-order-hijacking host. The Zscaler OpenClaw campaign (May 2025) shipped G2M.exe inside a malicious MSI alongside a malicious `g2m.dll` placed in the same directory so the signed binary loaded the attacker DLL on launch, then decrypted Remcos RAT shellcode. Hunt for `G2M.exe` running with a non-LogMeIn-signed `g2m.dll` next to it.
OS
Windows

FORENSIC EVIDENCE

Registry artifacts

Path
HKEY_LOCAL_MACHINE\WOW6432Node\Citrix\GoToMyPc
Description
Configuration settings including registration email
Path
HKEY_LOCAL_MACHINE\WOW6432Node\Citrix\GoToMyPc\GuestInvite
Description
Guest invites send to connect
Path
HKEY_CURRENT_USER\SOFTWARE\Citrix\GoToMyPc\FileTransfer\history
Description
hostname of the computer making connections and location of transferred files
Path
HKEY_USERS\<SID>\SOFTWARE\Citrix\GoToMyPc\FileTransfer\history
Description
hostname of the computer making connections and location of transferred files

FORENSIC EVIDENCE

Network artifacts

Description
N/A
Domains
  • *.GoToMyPC.com
Ports
Not recorded

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/gotomypc_registry_sigma.yml
Description
Detects potential registry activity of GoToMyPC RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/gotomypc_network_sigma.yml
Description
Detects potential network activity of GoToMyPC RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/gotomypc_files_sigma.yml
Description
Detects potential files activity of GoToMyPC RMM tool

References

Acknowledgements

Person
Phill Moore
Handle
@phillmoore
Person
Daniel Koifman
Handle
@KoifSec