logo

The Cryptography Trojan: Malicious Go Module Impersonates Foundational Library to Steal Passwords and Deploy Root Backdoors

ID: 911f2406-db4b-5fde-b395-7ea052bf6905

STIX ID: report--911f2406-db4b-5fde-b395-7ea052bf6905

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-03-02

Date Updated: 2026-04-23

Author: Ddos

...
...

Socket’s Threat Research Team uncovered a malicious Go module masquerading as golang.org/x/crypto that modifies ReadPassword to capture user passwords, exfiltrate them to attacker-controlled infrastructure, and fetch a shell script which implants persistence (adds an SSH key, alters iptables) and downloads disguised payloads; one payload is the Rekoobe Linux backdoor associated with espionage campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.