RMM
GoToMyPC
GoToMyPC is a remote monitoring and management (RMM) tool. More information will be added as it becomes available.
Tool overview
- Category
- RMM
- Research authors
- Nasreddine Bencherchali
- Created
- 2024-08-05
- Last modified
- 2024-08-05
- Privileges
- Not recorded
- Free / availability
- Not recorded
- Verification required
- Not recorded
- Supported platforms
- Not recorded
Executables & installation paths
- Filename
- AppCore.exe
- Filename
- g2comm.exe
- Filename
- g2file*.exe
- Filename
- g2fileh.exe
- Filename
- g2host.exe
- Filename
- g2m_download.exe
- Filename
- g2mainh.exe
- Filename
- G2MChat.exe
- Filename
- G2M.exe
- Filename
- G2MCodecInstExtractor.exe
- Filename
- G2MComm.exe
- Filename
- G2MCoreInstExtractor.exe
- Filename
- G2MFeedback.exe
- Filename
- G2MHost.exee
- Filename
- G2MInstaller.exe
- Filename
- G2MInstallerExtractor.exe
- Filename
- G2MInstHigh.exe
- Filename
- G2MLauncher.exe
- Filename
- G2MMatchMaking.exe
- Filename
- G2MMaterials.exe
- Filename
- G2MPolling.exe
- Filename
- G2MQandA.exe
- Filename
- G2MRecorder.exe
- Filename
- G2MScrUtil64.exe
- Filename
- G2MSessionControl.exe
- Filename
- G2MStart.exe
- Filename
- G2MTesting.exe
- Filename
- G2MTranscoder.exe
- Filename
- G2MUI.exe
- Filename
- G2MUninstall.exe
- Filename
- g2mupload.exe
- Filename
- g2mvideoconference.exe
- Filename
- G2MView.exe
- Filename
- g2printh.exe
- Filename
- g2quick.exe
- Filename
- g2svc.exe
- Filename
- g2tray.exe
- Filename
- gopcsrv.exe
- Filename
- GoToScrUtils.exe
- Filename
- GoTo.exe
- OriginalFileName
- Not recorded
- Description
- Not recorded
Installation paths
C:\Program Files (x86)\GoToMyPC\*
G2M.exe
%APPDATA%\GoToMeeting\G2M.exe
FORENSIC EVIDENCE
Disk artifacts
- File
- %AppData%\GoTo\Logs\goto.log
- Description
- N/A
- OS
- Windows
- File
- %APPDATA%\GoToMeeting\G2M.exe
- Description
- Legitimate, LogMeIn-signed GoToMeeting binary observed in the wild as a DLL-search-order-hijacking host. The Zscaler OpenClaw campaign (May 2025) shipped G2M.exe inside a malicious MSI alongside a malicious `g2m.dll` placed in the same directory so the signed binary loaded the attacker DLL on launch, then decrypted Remcos RAT shellcode. Hunt for `G2M.exe` running with a non-LogMeIn-signed `g2m.dll` next to it.
- OS
- Windows
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKEY_LOCAL_MACHINE\WOW6432Node\Citrix\GoToMyPc
- Description
- Configuration settings including registration email
- Path
- HKEY_LOCAL_MACHINE\WOW6432Node\Citrix\GoToMyPc\GuestInvite
- Description
- Guest invites send to connect
- Path
- HKEY_CURRENT_USER\SOFTWARE\Citrix\GoToMyPc\FileTransfer\history
- Description
- hostname of the computer making connections and location of transferred files
- Path
- HKEY_USERS\<SID>\SOFTWARE\Citrix\GoToMyPc\FileTransfer\history
- Description
- hostname of the computer making connections and location of transferred files
FORENSIC EVIDENCE
Network artifacts
- Description
- N/A
- Domains
- *.GoToMyPC.com
- Ports
- Not recorded
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/gotomypc_registry_sigma.yml
- Description
- Detects potential registry activity of GoToMyPC RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/gotomypc_network_sigma.yml
- Description
- Detects potential network activity of GoToMyPC RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/gotomypc_files_sigma.yml
- Description
- Detects potential files activity of GoToMyPC RMM tool
References
- https://support.logmeininc.com/gotomypc/help/what-are-the-optimal-firewall-configurations#
- https://support.goto.com/training/help/how-do-i-configure-gototraining-to-work-with-firewalls
- https://ruler-project.github.io/ruler-project/RULER/remote/Citrix%20GoToMyPC/
- https://www.zscaler.com/blogs/security-research/malicious-openclaw-skill-distributes-remcos-rat-and-ghostloader
- https://www.virustotal.com/gui/file/0d3ca4872e757fa406c10aa6893e831c2aaadce0687537d14fdce1702517b2d0/behavior
Acknowledgements
- Person
- Phill Moore
- Handle
- @phillmoore
- Person
- Daniel Koifman
- Handle
- @KoifSec