Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Go Module Poses as SSH Brute-Force Tool, Steals Credentials via Telegram Bot

Malicious Go Module Poses as SSH Brute-Force Tool, Steals Credentials via Telegram Bot

Posted on August 24, 2025August 24, 2025 By CWS

Aug 24, 2025Ravie LakshmananMalware / Provide Chain Safety
Cybersecurity researchers have found a malicious Go module that presents itself as a brute-force software for SSH however really incorporates performance to discreetly exfiltrate credentials to its creator.
“On the primary profitable login, the bundle sends the goal IP handle, username, and password to a hard-coded Telegram bot managed by the risk actor,” Socket researcher Kirill Boychenko mentioned.
The misleading bundle, named “golang-random-ip-ssh-bruteforce,” has been linked to a GitHub account referred to as IllDieAnyway (G3TT), which is at present now not accessible. Nonetheless, it continues to be out there on pkg.go[.]dev. It was printed on June 24, 2022.
The software program provide chain safety firm mentioned the Go module works by scanning random IPv4 addresses for uncovered SSH providers on TCP port 22, then making an attempt to brute-force the service utilizing an embedded username-password record and exfiltrating the profitable credentials to the attacker.
A notable facet of the malware is that it intentionally disables host key verification by setting “ssh.InsecureIgnoreHostKey” as a HostKeyCallback, thereby permitting the SSH consumer to just accept connections from any server no matter their id.
The wordlist is pretty simple, together with solely two usernames root and admin, and pairing them in opposition to weak passwords like root, check, password, admin, 12345678, 1234, qwerty, webadmin, webmaster, techsupport, letmein, and Passw@rd.

The malicious code runs in an infinite loop to generate the IPv4 addresses, with the bundle making an attempt concurrent SSH logins from the wordlist.
The main points are transmitted to a risk actor-controlled Telegram bot named “@sshZXC_bot” (ssh_bot) through the API, which then acknowledges the receipt of the credentials. The messages are despatched via the bot to an account with the deal with “@io_ping” (Gett).

An Web Archive snapshot of the now-removed GitHub account exhibits that IllDieAnyway, aka G3TT’s software program portfolio, included an IP port scanner, an Instagram profile information and media parser, and even a PHP-based command-and-control (C2) botnet referred to as Selica-C2.
Their YouTube channel, which stays accessible, hosts numerous short-form movies on “Methods to hack a Telegram bot” and what they declare to be the “strongest SMS bomber for the Russian Federation,” which might ship spam SMS texts and messages to VK customers utilizing a Telegram bot. It is assessed that the risk actor is of Russian origin.
“The bundle offloads scanning and password guessing to unwitting operators, spreads threat throughout their IPs, and funnels the successes to a single risk actor-controlled Telegram bot,” Boychenko mentioned.
“It disables host key verification, drives excessive concurrency, and exits after the primary legitimate login to prioritize fast seize. As a result of the Telegram Bot API makes use of HTTPS, the site visitors appears like regular internet requests and might slip previous coarse egress controls.”

The Hacker News Tags:Bot, BruteForce, Credentials, Malicious, Module, Poses, SSH, Steals, Telegram, Tool

Post navigation

Previous Post: New Gmail Phishing Attack Uses AI Prompt Injection to Evade Detection
Next Post: Apple 0-day, Chrome, Copilot Vulnerabilities and Cyber Attacks

Related Posts

AI Enhances Cloud Breach Investigation Speed for SOC Teams AI Enhances Cloud Breach Investigation Speed for SOC Teams The Hacker News
Malicious NuGet Package Targets Financial Sector Malicious NuGet Package Targets Financial Sector The Hacker News
Czech Republic Blames China-Linked APT31 Hackers for 2022 Cyberattack Czech Republic Blames China-Linked APT31 Hackers for 2022 Cyberattack The Hacker News
Chinese Cyber Group Exploits Google Workspace to Steal Emails Chinese Cyber Group Exploits Google Workspace to Steal Emails The Hacker News
Microsoft Addresses Active Windows Zero-Day Vulnerability Microsoft Addresses Active Windows Zero-Day Vulnerability The Hacker News
Developer Workstations Integral to Software Supply Chain Security Developer Workstations Integral to Software Supply Chain Security The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark