Threats Tagged 'go language'
View all threats tagged with 'go language'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'go language'
Click on any threat for detailed analysis and mitigation recommendations
BlueShell is an open-source remote access trojan developed in Go language, primarily used by Chinese-based threat actors. A variant of BlueShell has been identified in post-intrusion activities by APT groups including BlackTech, targeting organizations in Japan, South Korea, and Thailand. This variant differs from the original through a dedicated dropper mechanism, proxy server-based C2 communication, and anti-forensic capabilities. The dropper deploys the variant to /tmp/kthread, disguises it as a Linux kernel worker process, and removes filesystem traces. Recent variants observed since 2024 include XOR-encoded configuration data and proxy functionality, indicating continuous development. The malware performs hostname verification, validates C2 certificates, and implements commands for file transfer, remote shell, and SOCKS5 proxy capabilities. Join the discussion | AlienVault OTX General | 07/29/2026, 08:57:15 UTC Added: 07/29/2026, 11:52:25 UTC |
Salat Stealer is a Go-based information stealer that performs deep system reconnaissance and extracts sensitive data from compromised hosts. It targets browser credentials, cryptocurrency wallets, and communication platforms like Discord and Steam. The malware features advanced surveillance capabilities including desktop streaming, audio/video capture through microphone and webcam, and local file exfiltration. A notable distribution campaign bundled Salat Stealer with Xeno Executor, a gaming utility tool, transforming it into a full compromise vector. The malware employs sophisticated evasion techniques including disabling Windows Defender features through multiple PowerShell scripts, establishing persistence via registry run keys, and using token impersonation of lsass.exe to obtain elevated privileges. Loaders written in batch script and Rust programming language obfuscate deployment and bypass security controls. Join the discussion | AlienVault OTX General | 07/06/2026, 23:30:03 UTC Added: 07/07/2026, 14:14:38 UTC |
The Gentlemen is a ransomware-as-a-service operation tracked as Storm-2697, distinguished by combining robust per-file encryption using Curve25519 with XChaCha20 stream cipher alongside aggressive self-propagation capabilities designed for broad network compromise. Emerging in mid-2025 and transitioning to RaaS by September 2025, the operation recently partnered with BreachForums to recruit affiliates including penetration testers and initial access brokers. Written in Go and obfuscated with Garble, the ransomware employs double extortion tactics, encrypting data while exfiltrating sensitive information. It utilizes 21 distinct lateral movement techniques per target host, including PsExec, WMI, scheduled tasks, services, and PowerShell remoting. The malware disables defenses, deletes shadow copies and forensic artifacts, and can optionally wipe free disk space to prevent recovery, impacting organizations globally across education, transportation, healthcare, and finance sectors. Join the discussion | AlienVault OTX General | 05/28/2026, 19:56:31 UTC Added: 05/29/2026, 10:48:34 UTC |
PromptLock, a proof-of-concept AI-powered ransomware, leverages Lua scripts generated from hard-coded prompts to perform malicious activities across Windows, Linux, and macOS. Written in Go, it communicates with a locally hosted LLM through the Ollama API. The malware scans the filesystem, identifies sensitive information, and uses SPECK 128-bit encryption in ECB mode to encrypt files. It dynamically generates ransom notes and adapts its behavior based on the infected machine type. PromptLock's cross-platform compatibility and AI-driven script generation make it a significant concern for cybersecurity professionals, highlighting the need for advanced defensive strategies against evolving AI-powered threats. Join the discussion | AlienVault OTX General | 08/29/2025, 13:41:14 UTC Added: 08/29/2025, 15:32:48 UTC |
Showing 1 to 4 of 4 results