GoTo Resolve Tool’s Background Activities Compared to Ransomware Tactics
ID: bf63e403-ae90-5ff0-ac9b-6c665462d994
STIX ID: report--bf63e403-ae90-5ff0-ac9b-6c665462d994
Feed Name: HackRead
Point Wild's Lat61 team reports that components of GoTo Resolve (detected as HEURRemoteAdmin.GoToResolve.gen) can silently install to C:\Program Files (x86)\GoTo Resolve Unattended\, include a bundled control file named "32000~", and load the Windows Restart Manager (RstrtMgr.dll) to terminate security processes; although the software carries a valid GoTo Technologies digital signature, its silent persistence and ability to disable defenses make it a high-risk vector for remote access and subsequent ransomware or wiper attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
