logo

GoBruteforcer Botnet Targets 50K-plus Linux Servers

ID: 3f44a373-2088-5056-a76c-f83bd174c4eb

STIX ID: report--3f44a373-2088-5056-a76c-f83bd174c4eb

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-01-12

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

**Executive summary:** GoBruteforcer is an active, modular IRC-controlled botnet that brute-forces weak or AI-reused default credentials on internet-facing Linux services (FTP, MySQL, PostgreSQL, phpMyAdmin), turning compromised hosts into nodes for further scanning and attacks; Check Point observed improved obfuscation, persistence tricks, credential-tailored campaigns focused on cryptocurrency themes, and published IOCs, warning that insecure defaults and legacy stacks increase exposure and that mitigation requires stronger credential hygiene and secure configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.