Malicious Go Crypto Module Steals Passwords and Deploy Rekoobe Backdoor in Developer Environments
ID: 822c1bed-9607-5147-8d45-5678adcc9b5d
STIX ID: report--822c1bed-9607-5147-8d45-5678adcc9b5d
Feed Name: cybersecurityNews.com
A malicious Go module published as github.com/xinfeisoft/crypto mimicked the legitimate golang.org/x/crypto library and backdoored the ReadPassword helper to capture plaintext credentials, write them to /usr/share/nano/.lock, post them to attacker-controlled endpoints, and execute a fetched shell script; the script launched a five-stage Linux stager (snn50.txt) that added an SSH key to /home/ubuntu/.ssh/authorized_keys, weakened iptables policies, and downloaded/executed payloads (sss.mp5 and 555.mp5), with 555.mp5 confirmed as a Rekoobe backdoor communicating to 154.84.63.184:443 — the campaign is tied to supply-chain abuse and has links to APT31 activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
