logo

Malicious Go Package Steals Your SSH Credentials in a “Brute-Force” Scam

ID: 645890ed-f5cc-5b1b-b171-09578d127cba

STIX ID: report--645890ed-f5cc-5b1b-b171-09578d127cba

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2025-08-23

Date Updated: 2026-04-22

Author: Ddos

...
...

Socket’s Threat Research Team uncovered a malicious Go module published as a fast SSH brute-forcer that secretly sends any successfully guessed SSH credentials (ip:user:pass) to a hardcoded Telegram bot controlled by the actor IllDieAnyway (aka G3TT). The tool scans random IPv4 addresses for open port 22, attempts common username/password pairs, ignores host key verification, and uses the Telegram Bot API over HTTPS to exfiltrate credentials, exposing unwitting operators to legal and security consequences while funneling access to the attacker.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.