Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram
Blog post from Socket
Socket's Threat Research Team discovered a malicious Go module, golang-random-ip-ssh-bruteforce, which masquerades as a fast SSH brute forcer while secretly exfiltrating credentials via Telegram to a Russian-speaking threat actor known as IllDieAnyway. The package scans random IPv4 addresses for exposed SSH services, attempts authentication using a local username-password wordlist, and sends any successful credentials to a hardcoded Telegram bot, bypassing server identity checks. This tool exposes operators to legal risks by potentially violating laws and policies, as successful SSH access can lead to unauthorized sessions and further exploitation. The threat actor's GitHub profile hosts several offensive utilities, following a pattern of using Telegram for exfiltration. The malicious package's operation highlights the need for stringent supply chain security measures, such as code review and monitoring for suspicious network activity, to prevent the adoption of harmful software.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.