Threats Tagged 'golang'
View all threats tagged with 'golang'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'golang'
Click on any threat for detailed analysis and mitigation recommendations
GhostSocks is an emerging threat that turns compromised devices into residential proxy nodes, enabling attackers to evade detection. Originally marketed on Russian underground forums as Malware-as-a-Service, it has gained popularity due to its partnership with Lumma Stealer. Written in GoLang, GhostSocks uses SOCKS5 proxy protocol and TLS encryption to blend malicious traffic into normal network activity. It also incorporates backdoor functionality for running arbitrary commands and deploying additional payloads. Darktrace observed an increase in GhostSocks activity, detecting it alongside Lumma Stealer in customer networks. The malware's versatility in converting devices into proxy nodes while enabling covert network access illustrates how threat actors maximize the value of compromised infrastructure. Join the discussion | AlienVault OTX General | 03/31/2026, 16:14:29 UTC Added: 03/31/2026, 18:53:15 UTC |
A malicious Go module impersonating the legitimate golang.org/x/crypto has been discovered, containing a backdoor in ssh/terminal/terminal.go. This module captures passwords, exfiltrates them, and executes remote commands. The attack chain includes a Linux stager that installs an SSH key for persistence, weakens firewall settings, and deploys a Rekoobe backdoor. The campaign targets high-trust cryptography libraries and likely aims at cloud environments. The threat actor uses GitHub for staging and disguises payloads as media files. This sophisticated supply chain attack highlights the need for careful scrutiny of Go module changes and implementation of robust security measures in development workflows. Join the discussion | AlienVault OTX General | 02/27/2026, 05:11:11 UTC Added: 02/27/2026, 09:10:15 UTC |
A Pakistan-linked APT group conducted two campaigns targeting Indian government entities. The Gopher Strike campaign used PDFs with malicious links to deliver an ISO file containing GOGITTER, a Golang downloader that fetches payloads from private GitHub repositories. GITSHELLPAD, a Golang backdoor, was used for C2 communication via GitHub. GOSHELL, a Golang shellcode loader, deployed Cobalt Strike Beacon on specific hostnames. The attackers used various techniques including scheduled tasks for persistence, obfuscation, and environmental keying. Post-compromise activities involved system reconnaissance and data exfiltration. The campaign demonstrated sophisticated TTPs and custom-built tools, indicating a potentially new subgroup or parallel Pakistan-linked threat actor. Join the discussion | AlienVault OTX General | 01/26/2026, 21:19:21 UTC Added: 01/27/2026, 07:35:56 UTC |
GhostSocks is a Malware-as-a-Service (MAAS) that converts compromised devices into residential proxies, enabling threat actors to bypass anti-fraud mechanisms. Introduced in October 2023, it gained popularity after partnering with LummaStealer in February 2024. The malware, coded in Golang, uses obfuscation techniques and can be built as a 32-bit DLL or executable. It doesn't implement persistence mechanisms but focuses on SOCKS5 functionality. GhostSocks uses a configuration file or hardcoded config to connect to C2 servers, randomly generates credentials, and establishes a SOCKS5 connection using open-source libraries. Despite law enforcement actions against related platforms, GhostSocks continues to operate, posing ongoing risks of double victimization and long-term network access for cybercriminals. Join the discussion | AlienVault OTX General | 10/01/2025, 07:39:51 UTC Added: 10/01/2025, 08:49:39 UTC |
A newly emerged ransomware group called Dire Wolf has been observed since May 2025, targeting multiple sectors globally with a focus on manufacturing and technology. The group employs double extortion tactics, encrypting files and threatening to publish stolen data. Analysis of a Dire Wolf ransomware sample revealed it was written in Golang and uses a combination of Curve25519 and ChaCha20 algorithms for encryption. The malware disables event logging, terminates specific processes and services, and deletes backups and recovery options. Victims are given personalized ransom notes with login details for negotiation. As of writing, 16 victims across 11 nations have been listed on the group's leak site, with the US and Thailand being the most affected. Join the discussion | AlienVault OTX General | 07/02/2025, 07:12:53 UTC Added: 07/02/2025, 07:24:34 UTC |
Chaos RAT is an open-source remote administration tool written in Golang that has evolved since 2022 to support both Linux and Windows platforms. A critical vulnerability identified as CVE-2024-30850 exists in its web control panel, allowing remote code execution on the server. Although currently limited in usage, Chaos RAT's low detection profile enables threat actors to perform espionage, data exfiltration, and maintain persistent access. The malware employs multiple techniques including privilege escalation, persistence, and command and control communications. Organizations should prioritize patching the vulnerable control panel, restrict access to administrative interfaces, and monitor for indicators of compromise. The threat is assessed as high severity due to its potential impact and ease of exploitation without user interaction. Patch status is not confirmed; no official fix or patch links are provided. The affected platforms include Linux and Windows systems. No specific countries are identified as targeted, but those with significant Linux and Windows server use and strategic geopolitical interests may be at higher risk. Join the discussion | AlienVault OTX General | 06/06/2025, 11:02:59 UTC Added: 06/09/2025, 10:55:44 UTC |
Showing 1 to 6 of 6 results