logo

The “Go Client” Trap: Why Your RustDesk ID is Currently Under Automated Botnet Siege

ID: cec0686a-5eee-5482-ae8b-4cd17ae55738

STIX ID: report--cec0686a-5eee-5482-ae8b-4cd17ae55738

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-03

Date Updated: 2026-04-23

Author: Ddos

...
...

In late January 2026 an automated botnet campaign targeted RustDesk users by mass-sending connection requests from clients labeled "Go Client" to solicit user acceptance; accepted connections allow the botnet to take control, execute scripted commands to deploy secondary malware, and maintain persistence. The campaign uses broad automated reconnaissance to find active RustDesk IDs and relies on user consent rather than exploiting software vulnerabilities. The report includes observable characteristics (connection label, diverse source IPs) and concrete mitigations: require passwords for connections, enforce high-entropy passwords and 2FA or IP whitelisting, use ACLs via the Professional self-hosted edition, and consider self-hosting while protecting server IPs and keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.