logo

GoTo Resolve Tool’s Background Activities Compared to Ransomware Tactics

ID: bf63e403-ae90-5ff0-ac9b-6c665462d994

STIX ID: report--bf63e403-ae90-5ff0-ac9b-6c665462d994

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-01-28

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Point Wild's Lat61 team reports that components of GoTo Resolve (detected as HEURRemoteAdmin.GoToResolve.gen) can silently install to C:\Program Files (x86)\GoTo Resolve Unattended\, include a bundled control file named "32000~", and load the Windows Restart Manager (RstrtMgr.dll) to terminate security processes; although the software carries a valid GoTo Technologies digital signature, its silent persistence and ability to disable defenses make it a high-risk vector for remote access and subsequent ransomware or wiper attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.