GoBruteforcer Botnet Attacking Linux Servers Worldwide – 50,000 Internet-facing Servers at Risk
The GoBruteforcer botnet is actively targeting Linux servers globally. Utilizing a Go-based architecture, this botnet focuses on brute-forcing weak passwords on exposed internet services such as FTP, MySQL, PostgreSQL, and phpMyAdmin.
The GoBruteforcer botnet is actively targeting Linux servers globally. Utilizing a Go-based architecture, this botnet focuses on brute-forcing weak passwords on exposed internet services such as FTP, MySQL, PostgreSQL, and phpMyAdmin.
Check Point Research has documented a new variant of this malware for 2025. This updated version incorporates technical enhancements and has compromised tens of thousands of servers.
The botnet employs a modular infection chain, consisting of web shells, downloaders, IRC bots, and brute-forcing components. Check Point's analysis indicates over 50,000 internet-facing servers could be vulnerable to GoBruteforcer attacks, along with 5.7 million FTP servers, 2.23 million MySQL servers, and 560,000 PostgreSQL servers exposed on their default ports.
The current campaigns are fueled by the mass reuse of AI-generated server deployment examples that include common usernames and weak defaults, alongside legacy web stacks like XAMPP that expose services with minimal hardening. Researchers found that the botnet uses common operational usernames such as "appuser" and "myuser" in brute-force credential lists, which are also commonly suggested by large language models.
Analysis reveals that GoBruteforcer's credential lists overlap with approximately 2.44% of a database containing 10 million leaked passwords. Google’s 2024 Cloud Threat Horizons report identified weak or missing credentials as accounting for 47.2% of initial access vectors in compromised cloud environments, supporting the economic viability of this method for threat actors.
The 2025 variant includes significant updates from earlier versions first documented in 2023. The IRC bot component has been rewritten in Go and obfuscated using Garbler, replacing the previous C-based implementation. The malware now employs process-masking techniques to hide command-line arguments from monitoring tools.
Researchers identified a cryptocurrency-focused campaign where additional Go-based tools were deployed on compromised hosts, including a TRON balance scanner and token-sweep utilities for TRON and Binance Smart Chain. The botnet maintains its resilience through hardcoded fallback C2 addresses, domain-based recovery paths, and the potential to promote infected hosts to serve as distribution nodes or IRC relays.
Organizations can mitigate GoBruteforcer risks by implementing strong password policies, disabling unnecessary internet-facing services, enforcing multi-factor authentication, and monitoring for suspicious login attempts.
Type IOC Description / Notes
The GoBruteforcer botnet is actively targeting Linux servers globally.
Network 190.14.37[.]10 C&C (reported active endpoint).
Network 93.113.25[.]114 C&C (reported active endpoint).
Network fi.warmachine[.]su C&C (as provided).
Network xyz.yuzgebhmwu[.]ru C&C (reported active endpoint).
Network pool.breakfastidentity[.]ru C&C (as provided).
Network pandaspandas[.]pm C&C (as provided; appears twice in the provided list).
Network my.magicpandas[.]fun C&C (as provided).
File hash (SHA-256) 7423b6424b26c7a32ae2388bc23bef386c30e9a6acad2b63966188cb49c283ad IRC Bot (x86) (as provided).
File hash (SHA-256) 8fd41cb9d73cb68da89b67e9c28228886b8a4a5858c12d5bb1bffb3c4addca7c IRC Bot (x86) (as provided).
File hash (SHA-256) bd219811c81247ae0b6372662da28eab6135ece34716064facd501c45a3f4c0d IRC Bot (arm) (as provided).
File hash (SHA-256) b0c6fe570647fdedd72c920bb40621fdb0c55ed217955557ea7c27544186aeec IRC Bot (arm64) (as provided).
File hash (SHA-256) ab468da7e50e6e73b04b738f636da150d75007f140e468bf75bc95e8592468e5 Bruteforcer (x86) (as provided).
File hash (SHA-256) 4fbea12c44f56d5733494455a0426b25db9f8813992948c5fbb28f38c6367446 Bruteforcer (x64) (as provided).
File hash (SHA-256) 64e02ffb89ae0083f4414ef8a72e6367bf813701b95e3d316e3dfbdb415562c4 Bruteforcer (arm) (as provided).
File hash (SHA-256) c7886535973fd9911f8979355eae5f5abef29a89039c179842385cc574dfa166 Bruteforcer (arm64) (as provided).
Based on reporting by Cyber Security News.
