logo

GobRAT malware written in Go language targeting Linux routers

ID: 552af1e4-48b7-572e-989d-3b34fd8ba509

STIX ID: report--552af1e4-48b7-572e-989d-3b34fd8ba509

Feed Name: JPCERT Blog

Threat Score
72/100

Date Published: 2023-05-29

Date Updated: 2026-04-19

Author: 増渕 維摩(Yuma Masubuchi)

...
...

JPCERT/CC confirmed router infections in Japan by GobRAT, a Go-based RAT that targets publicly accessible router web UIs to deploy a loader, persistence scripts, and a packed multi-architecture payload; the report details the attack flow, persistence and daemon scripts, gob-over-TLS communications, AES-128-CTR string encryption with hard-coded key/IV, 22 C2-driven commands (including SOCKS5, frpc, remote execution, scanning/attacks), C2 domains, and hashes for scripts and malware samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.