New GoBruteforcer attack wave targets crypto, blockchain projects
ID: cf215366-89d0-56e2-ae6b-7984dd75e6aa
STIX ID: report--cf215366-89d0-56e2-ae6b-7984dd75e6aa
Feed Name: Bleeping Computer
Threat Score
A Golang-based botnet called GoBruteforcer is actively targeting exposed FTP, MySQL, PostgreSQL and phpMyAdmin services—often on outdated XAMPP stacks or systems using AI-generated default credentials—to deploy web shells, brute-force logins, and install modules that scan and drain cryptocurrency wallets; Check Point researchers estimate over 50,000 potentially vulnerable internet-facing servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
