Skip to content

Malware

WellMess

WellMess is A Remote Access Trojan written in GoLang and .NET.

WellMess is A Remote Access Trojan written in GoLang and .NET. It has hard-coded User-Agents. Attackers deploy WellMess using separate tools which also allow lateral movement, for example "gost". Command and Control traffic is handled via HTTP using the Set-Cookie field and message body.


Family metadata imported from Malpedia (Fraunhofer FKIE).