logo

BLUERABBIT: A Golang-Based Backdoor with Ransomware…

ID: c3c9dd25-3c35-56cb-ac49-9ca4e53af169

STIX ID: report--c3c9dd25-3c35-56cb-ac49-9ca4e53af169

Feed Name: Binary Defense Blog

Threat Score
88/100

Date Published: 2026-06-08

Date Updated: 2026-06-09

...
...

BLUERABBIT is a Golang backdoor attributed to a likely Iran-nexus actor observed in mid-to-late March 2026 that leverages enterprise protocols (RabbitMQ/AMQP, Redis, MinIO/S3) for resilient C2 and large-file exfiltration. The malware provides remote access (VNC-like control), extensive system profiling, staged exfiltration to MinIO, file encryption appending a .candy extension, and two destructive disk-wiping modes (single-pass random and multi-pass zero/random/0xFF) that can render systems unrecoverable; the report includes persistence and anti-recovery techniques, detection opportunities, and multiple IoCs (SHA-256, IPs, JA3/JA4).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.