BLUERABBIT: A Golang-Based Backdoor with Ransomware…
ID: c3c9dd25-3c35-56cb-ac49-9ca4e53af169
STIX ID: report--c3c9dd25-3c35-56cb-ac49-9ca4e53af169
Feed Name: Binary Defense Blog
BLUERABBIT is a Golang backdoor attributed to a likely Iran-nexus actor observed in mid-to-late March 2026 that leverages enterprise protocols (RabbitMQ/AMQP, Redis, MinIO/S3) for resilient C2 and large-file exfiltration. The malware provides remote access (VNC-like control), extensive system profiling, staged exfiltration to MinIO, file encryption appending a .candy extension, and two destructive disk-wiping modes (single-pass random and multi-pass zero/random/0xFF) that can render systems unrecoverable; the report includes persistence and anti-recovery techniques, detection opportunities, and multiple IoCs (SHA-256, IPs, JA3/JA4).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
