Global GoBruteforcer Botnet Campaign Threatens 50,000 Linux Servers
ID: 3d991c60-f615-5579-a24c-4c708cb1bc4d
STIX ID: report--3d991c60-f615-5579-a24c-4c708cb1bc4d
Feed Name: GBHackers
A modular Go-based botnet named GoBruteforcer is actively targeting exposed Linux services (FTP, MySQL, PostgreSQL, phpMyAdmin) worldwide by brute-forcing credentials via an infection chain of web shells, downloaders, IRC bots and bruteforcer modules. Researchers report a more advanced 2025 variant with heavy obfuscation, process-masking, cron-based persistence, architecture-specific worker pools, and dynamic credential lists; campaigns have targeted cryptocurrency projects and resulted in successful fund thefts. The report estimates tens of thousands of vulnerable instances and urges immediate audits, stronger authentication, disabling default accounts, and network segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
