GoBruteforcer botnet expands against crypto and blockchain project databases
Malware Activity
Summary
Hide ▲
Show ▼
The GoBruteforcer botnet has entered a new wave of attacks that targets cryptocurrency and blockchain project databases and turns Linux servers into credential-brute-forcing nodes. The malware now uses obfuscated IRC bot code, improved persistence, process masking, and dynamic credential lists to reach FTP, MySQL, PostgreSQL, and phpMyAdmin. Infected hosts can also host payloads and act as backup C2, increasing resilience. The observed intrusion path starts with exposed XAMPP FTP access and a PHP web shell that downloads and runs the bot.
Related Happenings
XQUIC XRING remote crash security flaw
Vulnerability
H score1
First: 10.07.2026 14:47
Last: 10.07.2026 14:47
Sources 1
About this happening:
XQUIC's XRING flaw leaves HTTP/3 servers exposed to remote crashes through valid QPACK traffic, with no patch available. The bug needs no login and no malforme...
XQUIC XRING remote crash security flaw
VulnerabilityAbout this happening: XQUIC's XRING flaw leaves HTTP/3 servers exposed to remote crashes through valid QPACK traffic, with no patch available. The bug needs no login and no malforme...
IronWorm npm supply-chain infection and self-propagation
Malware Activity
H score15
First: 04.06.2026 18:25
Last: 04.06.2026 18:25
Sources 1
About this happening:
IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
IronWorm npm supply-chain infection and self-propagation
Malware ActivityAbout this happening: IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
TrueChaos TrueConf CVE-2026-3502 campaign targeting Southeast Asian government entities
Campaign
H score79
First: 02.04.2026 00:35
Last: 02.04.2026 00:35
Sources 1
About this happening:
The TrueChaos campaign has been exploiting CVE-2026-3502 in TrueConf zero-day attacks against government entities in Southeast Asia, turning compromised servers in...
TrueChaos TrueConf CVE-2026-3502 campaign targeting Southeast Asian government entities
CampaignAbout this happening: The TrueChaos campaign has been exploiting CVE-2026-3502 in TrueConf zero-day attacks against government entities in Southeast Asia, turning compromised servers in...
AVRecon malware for Linux powering SocksEscort proxy network
Malware Activity
H score19
First: 12.03.2026 18:19
Last: 12.03.2026 18:19
Sources 1
About this happening:
The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
AVRecon malware for Linux powering SocksEscort proxy network
Malware ActivityAbout this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
Uphero/hero trojanized 7-Zip installer proxyware activity
Malware Activity
H score15
First: 10.02.2026 21:12
Last: 10.02.2026 21:12
Sources 1
About this happening:
A trojanized 7-Zip installer is now dropping Uphero/hero payloads that turn Windows hosts into residential proxy nodes, letting attackers route traffic through vic...
Uphero/hero trojanized 7-Zip installer proxyware activity
Malware ActivityAbout this happening: A trojanized 7-Zip installer is now dropping Uphero/hero payloads that turn Windows hosts into residential proxy nodes, letting attackers route traffic through vic...
Timeline
-
12.01.2026 12:48 3 articles · 6mo ago
GoBruteforcer campaign disclosed against crypto and blockchain project databases
Initial DisclosureGoBruteforcer campaigns are targeting cryptocurrency and blockchain project databases on Linux servers to build a botnet that brute-forces credentials for FTP, MySQL, PostgreSQL, and phpMyAdmin. The observed access path often starts with an internet-exposed FTP service on XAMPP, followed by a PHP web shell upload that downloads and executes an updated IRC bot, while compromised hosts can also host payloads, provide backup C2, and stage a module that queries TRON balances through tronscanapi[.]com to find accounts with non-zero funds.
Show sources
- GoBruteforcer Botnet Targets Crypto Project Databases by Exploiting Weak Credentials — thehackernews.com — 12.01.2026 12:48
- GoBruteforcer Botnet Targets Crypto Project Databases by Exploiting Weak Credentials — thehackernews.com — 12.01.2026 12:48
- GoBruteforcer Botnet Targets 50K-plus Linux Servers — www.darkreading.com — 12.01.2026 23:19