GoBruteforcer Botnet Targets Linux Servers
ID: 2cc564a7-c2ad-5a23-ba55-038742b800a5
STIX ID: report--2cc564a7-c2ad-5a23-ba55-038742b800a5
Feed Name: Infosecurity Magazine (News)
Threat Score
GoBruteforcer is an active botnet campaign that brute-forces weak or default credentials on internet-exposed Linux services (FTP, MySQL, PostgreSQL, phpMyAdmin), turning compromised hosts into scanning/attack nodes; a newer Go-based, obfuscated variant with stronger persistence has been observed and researchers estimate over 50,000 publicly accessible servers may be vulnerable, with evidence of crypto-focused theft activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
