Tuesday, 26 August

Monday, 25 August2025

Malicious Go Module Masquerading as SSH Brute-Force Tool Steals Login Credentials via Telegram

Malicious Go Module Masquerading as SSH Brute-Force Tool Steals Login Credentials via Telegram
Security researchers have uncovered a deceptive Go module namedgolang-random-ip-ssh-bruteforcethat masquerades as an SSH brute-force scanner. Once a login succeeds, it stealthily sends the target IP, username, and password to a malicious Telegram bot. It bypasses host key checks, attempts high-concurrency brute-forcing using common credentials (e.g., root, admin, 12345678), and relays results to the attacker via Telegramevading detection and exploiting unwitting operators.

Subscribe To Our Newsletter.

Full Name
Email