The Cryptography Trojan: Malicious Go Module Impersonates Foundational Library to Steal Passwords and Deploy Root Backdoors
ID: 911f2406-db4b-5fde-b395-7ea052bf6905
STIX ID: report--911f2406-db4b-5fde-b395-7ea052bf6905
Feed Name: securityonline.info
Threat Score
Socket’s Threat Research Team uncovered a malicious Go module masquerading as golang.org/x/crypto that modifies ReadPassword to capture user passwords, exfiltrate them to attacker-controlled infrastructure, and fetch a shell script which implants persistence (adds an SSH key, alters iptables) and downloads disguised payloads; one payload is the Rekoobe Linux backdoor associated with espionage campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
