Find notable cyber news and cases, enriched with sources, timelines, and signals.

GoBruteforcer botnet expands against crypto and blockchain project databases

Malware Activity
First reported
Last updated
Happening score
H score 27
2 unique sources, 2 articles

Summary

Hide ▲

The GoBruteforcer botnet has entered a new wave of attacks that targets cryptocurrency and blockchain project databases and turns Linux servers into credential-brute-forcing nodes. The malware now uses obfuscated IRC bot code, improved persistence, process masking, and dynamic credential lists to reach FTP, MySQL, PostgreSQL, and phpMyAdmin. Infected hosts can also host payloads and act as backup C2, increasing resilience. The observed intrusion path starts with exposed XAMPP FTP access and a PHP web shell that downloads and runs the bot.

Related Happenings

XQUIC XRING remote crash security flaw

Vulnerability
H score1 First: 10.07.2026 14:47 Last: 10.07.2026 14:47 Sources 1

About this happening: XQUIC's XRING flaw leaves HTTP/3 servers exposed to remote crashes through valid QPACK traffic, with no patch available. The bug needs no login and no malforme...

IronWorm npm supply-chain infection and self-propagation

Malware Activity
H score15 First: 04.06.2026 18:25 Last: 04.06.2026 18:25 Sources 1

About this happening: IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...

TrueChaos TrueConf CVE-2026-3502 campaign targeting Southeast Asian government entities

Campaign
H score79 First: 02.04.2026 00:35 Last: 02.04.2026 00:35 Sources 1

About this happening: The TrueChaos campaign has been exploiting CVE-2026-3502 in TrueConf zero-day attacks against government entities in Southeast Asia, turning compromised servers in...

AVRecon malware for Linux powering SocksEscort proxy network

Malware Activity
H score19 First: 12.03.2026 18:19 Last: 12.03.2026 18:19 Sources 1

About this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...

Uphero/hero trojanized 7-Zip installer proxyware activity

Malware Activity
H score15 First: 10.02.2026 21:12 Last: 10.02.2026 21:12 Sources 1

About this happening: A trojanized 7-Zip installer is now dropping Uphero/hero payloads that turn Windows hosts into residential proxy nodes, letting attackers route traffic through vic...

Timeline

  1. 12.01.2026 12:48 3 articles · 6mo ago

    GoBruteforcer campaign disclosed against crypto and blockchain project databases

    Initial Disclosure

    GoBruteforcer campaigns are targeting cryptocurrency and blockchain project databases on Linux servers to build a botnet that brute-forces credentials for FTP, MySQL, PostgreSQL, and phpMyAdmin. The observed access path often starts with an internet-exposed FTP service on XAMPP, followed by a PHP web shell upload that downloads and executes an updated IRC bot, while compromised hosts can also host payloads, provide backup C2, and stage a module that queries TRON balances through tronscanapi[.]com to find accounts with non-zero funds.

    Show sources