Malicious Go Package Steals Your SSH Credentials in a “Brute-Force” Scam
ID: 645890ed-f5cc-5b1b-b171-09578d127cba
STIX ID: report--645890ed-f5cc-5b1b-b171-09578d127cba
Feed Name: securityonline.info
Socket’s Threat Research Team uncovered a malicious Go module published as a fast SSH brute-forcer that secretly sends any successfully guessed SSH credentials (ip:user:pass) to a hardcoded Telegram bot controlled by the actor IllDieAnyway (aka G3TT). The tool scans random IPv4 addresses for open port 22, attempts common username/password pairs, ignores host key verification, and uses the Telegram Bot API over HTTPS to exfiltrate credentials, exposing unwitting operators to legal and security consequences while funneling access to the attacker.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
