- Joined
- Jan 22, 2026
- Messages
- 101
- Reaction score
- 955
Why has a tool for helping users suddenly become the perfect gift for hackers?

During routine system monitoring, Point Wild specialists discovered a potentially unwanted application associated with the GoTo Resolve remote access program. Despite the fact that this tool is intended for legitimate use by IT specialists, its functionality can be used for purposes that pose a security threat.
The analysis showed that the executable file "GoToResolveUnattended.exe " it belongs to the GoTo Resolve Unattended Access remote access component, which allows you to connect to computers without user intervention. In this case, the installation takes place without explicit notification, and background threads are created during the startup process. The program is registered in the system on an ongoing basis and is located in the folder at "C:\Program Files (x86)\GoTo Resolve Unattended».
Although the file has a digital signature from GoTo Technologies USA, LLC, the presence of a signature does not exclude the possibility of abuse in case of compromise or circumvention of control. Such programs often become a tool for cybercriminals, who can use them for covert remote access, installation of malicious modules, advertising, or other actions without the knowledge of the device owner.
One of the alarming signals was the loading of the dynamic library "RstrtMgr.dll ", previously seen in campaigns using ransomware and viper programs. Such libraries allow you to terminate processes that interfere with malicious activity, including data encryption. The presence of this library may indicate an attempt to protect against analysis or provide control over an infected system.
An auxiliary file with instructions for installing and managing the program was also found in the archive with the sample under study. This additionally confirms the existence of a hidden installation mechanism and increases the risk of unauthorized use.
The program was recognized by the UltraAV antivirus under the designation HEURRemoteAdmin.GoToResolve.gen, which confirms its potential danger in corporate and user environments. Without proper monitoring, such software can significantly expand the attack surface and become an entry point for other malicious components.
Experts recommend that organizations use prevention measures, including limiting the launch of third-party applications, constant monitoring of endpoints, and raising employee awareness of the risks associated with remote access tools. If such programs are detected without official permission, it is recommended to remove them immediately.

During routine system monitoring, Point Wild specialists discovered a potentially unwanted application associated with the GoTo Resolve remote access program. Despite the fact that this tool is intended for legitimate use by IT specialists, its functionality can be used for purposes that pose a security threat.
The analysis showed that the executable file "GoToResolveUnattended.exe " it belongs to the GoTo Resolve Unattended Access remote access component, which allows you to connect to computers without user intervention. In this case, the installation takes place without explicit notification, and background threads are created during the startup process. The program is registered in the system on an ongoing basis and is located in the folder at "C:\Program Files (x86)\GoTo Resolve Unattended».
Although the file has a digital signature from GoTo Technologies USA, LLC, the presence of a signature does not exclude the possibility of abuse in case of compromise or circumvention of control. Such programs often become a tool for cybercriminals, who can use them for covert remote access, installation of malicious modules, advertising, or other actions without the knowledge of the device owner.
One of the alarming signals was the loading of the dynamic library "RstrtMgr.dll ", previously seen in campaigns using ransomware and viper programs. Such libraries allow you to terminate processes that interfere with malicious activity, including data encryption. The presence of this library may indicate an attempt to protect against analysis or provide control over an infected system.
An auxiliary file with instructions for installing and managing the program was also found in the archive with the sample under study. This additionally confirms the existence of a hidden installation mechanism and increases the risk of unauthorized use.
The program was recognized by the UltraAV antivirus under the designation HEURRemoteAdmin.GoToResolve.gen, which confirms its potential danger in corporate and user environments. Without proper monitoring, such software can significantly expand the attack surface and become an entry point for other malicious components.
Experts recommend that organizations use prevention measures, including limiting the launch of third-party applications, constant monitoring of endpoints, and raising employee awareness of the risks associated with remote access tools. If such programs are detected without official permission, it is recommended to remove them immediately.