Skip to main content

Threats Tagged 'golang backdoor'

View all threats tagged with 'golang backdoor'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: golang backdoor

Threats Tagged 'golang backdoor'

Click on any threat for detailed analysis and mitigation recommendations

In October 2025, Microsoft Threat Intelligence discovered GigaWiper, a sophisticated Golang-based backdoor that combines command-and-control capabilities with multiple destructive payloads. This versatile implant consolidates functionality from at least three separate malware families: a standalone wiper operating at physical disk level, a destructive component derived from Crucio ransomware that encrypts files with randomly generated unsaved keys, and a reimplemented version of FlockWiper with enhanced multi-pass secure wiping. The backdoor provides 20 different commands enabling threat actors to maintain control, execute operations, collect system information, and trigger destructive actions on demand. GigaWiper establishes persistence through scheduled tasks, communicates via RabbitMQ and Redis servers, and can perform disk wiping, fake ransomware encryption, screen recording, VNC-like remote control, and system-level sabotage including BSOD triggers and event log clearing.

Join the discussion

FlexibleFerret is a sophisticated macOS malware campaign leveraging fake job assessment scams and social engineering to infect victims. It uses multi-stage attacks starting with JavaScript files on fraudulent recruitment websites that trick users into executing shell commands. These commands download and run a Golang backdoor that establishes persistence, enabling data theft and remote control. The malware can collect system info, steal Chrome credentials, upload/download files, and execute arbitrary commands. Attackers exfiltrate stolen data via Dropbox, complicating detection. The campaign is attributed to DPRK-aligned threat actors and targets macOS users globally. No CVSS score exists, but the threat is medium severity due to social engineering reliance and macOS focus. European organizations with macOS endpoints, especially in tech and government sectors, face risks. Mitigations include user education on phishing, restricting script execution, monitoring unusual Dropbox traffic, and deploying endpoint detection tuned for macOS threats.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: golang backdoor
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses