Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

GoBruteforcer Botnet Attacking Linux Servers Worldwide – 50,000 Internet-facing Servers at Risk

The GoBruteforcer botnet is actively targeting Linux servers globally. Utilizing a Go-based architecture, this botnet focuses on brute-forcing weak passwords on exposed internet services such as FTP, MySQL, PostgreSQL, and phpMyAdmin.

The GoBruteforcer botnet is actively targeting Linux servers globally. Utilizing a Go-based architecture, this botnet focuses on brute-forcing weak passwords on exposed internet services such as FTP, MySQL, PostgreSQL, and phpMyAdmin.

Check Point Research has documented a new variant of this malware for 2025. This updated version incorporates technical enhancements and has compromised tens of thousands of servers.

The botnet employs a modular infection chain, consisting of web shells, downloaders, IRC bots, and brute-forcing components. Check Point's analysis indicates over 50,000 internet-facing servers could be vulnerable to GoBruteforcer attacks, along with 5.7 million FTP servers, 2.23 million MySQL servers, and 560,000 PostgreSQL servers exposed on their default ports.

The current campaigns are fueled by the mass reuse of AI-generated server deployment examples that include common usernames and weak defaults, alongside legacy web stacks like XAMPP that expose services with minimal hardening. Researchers found that the botnet uses common operational usernames such as "appuser" and "myuser" in brute-force credential lists, which are also commonly suggested by large language models.

Analysis reveals that GoBruteforcer's credential lists overlap with approximately 2.44% of a database containing 10 million leaked passwords. Google’s 2024 Cloud Threat Horizons report identified weak or missing credentials as accounting for 47.2% of initial access vectors in compromised cloud environments, supporting the economic viability of this method for threat actors.

The 2025 variant includes significant updates from earlier versions first documented in 2023. The IRC bot component has been rewritten in Go and obfuscated using Garbler, replacing the previous C-based implementation. The malware now employs process-masking techniques to hide command-line arguments from monitoring tools.

Researchers identified a cryptocurrency-focused campaign where additional Go-based tools were deployed on compromised hosts, including a TRON balance scanner and token-sweep utilities for TRON and Binance Smart Chain. The botnet maintains its resilience through hardcoded fallback C2 addresses, domain-based recovery paths, and the potential to promote infected hosts to serve as distribution nodes or IRC relays.

Organizations can mitigate GoBruteforcer risks by implementing strong password policies, disabling unnecessary internet-facing services, enforcing multi-factor authentication, and monitoring for suspicious login attempts.

Type IOC Description / Notes

The GoBruteforcer botnet is actively targeting Linux servers globally.
Brian Shaw · Thehackingpost

Network 190.14.37[.]10 C&C (reported active endpoint).

Network 93.113.25[.]114 C&C (reported active endpoint).

Network fi.warmachine[.]su C&C (as provided).

Network xyz.yuzgebhmwu[.]ru C&C (reported active endpoint).

Network pool.breakfastidentity[.]ru C&C (as provided).

Network pandaspandas[.]pm C&C (as provided; appears twice in the provided list).

Network my.magicpandas[.]fun C&C (as provided).

File hash (SHA-256) 7423b6424b26c7a32ae2388bc23bef386c30e9a6acad2b63966188cb49c283ad IRC Bot (x86) (as provided).

Advertisement

File hash (SHA-256) 8fd41cb9d73cb68da89b67e9c28228886b8a4a5858c12d5bb1bffb3c4addca7c IRC Bot (x86) (as provided).

File hash (SHA-256) bd219811c81247ae0b6372662da28eab6135ece34716064facd501c45a3f4c0d IRC Bot (arm) (as provided).

File hash (SHA-256) b0c6fe570647fdedd72c920bb40621fdb0c55ed217955557ea7c27544186aeec IRC Bot (arm64) (as provided).

File hash (SHA-256) ab468da7e50e6e73b04b738f636da150d75007f140e468bf75bc95e8592468e5 Bruteforcer (x86) (as provided).

File hash (SHA-256) 4fbea12c44f56d5733494455a0426b25db9f8813992948c5fbb28f38c6367446 Bruteforcer (x64) (as provided).

File hash (SHA-256) 64e02ffb89ae0083f4414ef8a72e6367bf813701b95e3d316e3dfbdb415562c4 Bruteforcer (arm) (as provided).

File hash (SHA-256) c7886535973fd9911f8979355eae5f5abef29a89039c179842385cc574dfa166 Bruteforcer (arm64) (as provided).

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories