Skip to content

Malware

WellMess

WellMess is A Remote Access Trojan written in GoLang and .NET.

WellMess is a Windows malware family.

Background

WellMess is a remote access trojan implemented in both GoLang and .NET, and it carries hard-coded User-Agent strings. Operators rely on separate utilities, such as "gost", to deploy WellMess and to move laterally. Its Command and Control communication runs over HTTP, conveyed through the Set-Cookie field and the message body.


Source: Malpedia (Fraunhofer FKIE).