GoBruteforcer Botnet Attacking Linux Servers Worldwide – 50,000 Internet-facing Servers at Risk
ID: 9e6b0937-8b8c-501b-9686-3a1d5e561064
STIX ID: report--9e6b0937-8b8c-501b-9686-3a1d5e561064
Feed Name: cybersecurityNews.com
Threat Score
GoBruteforcer is a sophisticated Go-based botnet actively brute-forcing weak credentials across internet-exposed services (FTP, MySQL, PostgreSQL, phpMyAdmin), leveraging AI-reused default usernames and legacy stacks like XAMPP; the 2025 variant adds heavy Go-based obfuscation, process-masking, modular infection chains, and crypto-focused tooling, with tens of thousands of compromises reported and multiple C2s and SHA-256 IOCs provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
