Skip to content
Detecteam
  • CompanyExpand
    • Founders Story
    • The Team
  • ProductExpand
    • About Us
  • SolutionsExpand
    • Use Cases
  • ResourcesExpand
    • Detecteam Blogs
    • Contact Us
Twitter Linkedin
Detecteam
Blog · Scenario

GoBruteforcer Botnet

Avatar photoByDetecteam 2023-07-032023-07-03

TLP

TLP CLEAR

Authors

Sebastien Tricaud, David Deflache

Summary

GoBruteforcer is a newly discovered Golang-based malware that targets web servers running phpMyAdmin, MySQL, FTP, and Postgres services. The malware was found on a legitimate website and utilizes different processor architectures. It deploys an IRC bot for communication with the attacker’s server and uses specific conditions and weak passwords to successfully execute its attack. Palo Alto Networks offers protections against malware like GoBruteforcer through their security services. The malware’s attack chain involves scanning the network, gaining access via brute force, deploying the IRC bot, and querying the victim system with a PHP web shell. GoBruteforcer primarily targets Unix-like platforms and is believed to be actively developed with potential changes to its infection vectors and payloads.

DATA

gobruteforcer.pcapngDownload

TIMELINE

CATEGORY

Malware

references

  • https://unit42.paloaltonetworks.com/gobruteforcer-golang-botnet/

MITRE ATT&CK

Post Tags: #T1018 - Remote System Discovery#T1036.005 - Masquerading: Match Legitimate Name or Location#T1053.005 - Scheduled Task/Job: Scheduled Task#T1059.003 - Windows Command Shell#T1071 - Application Layer Protocol#T1078 - Valid Accounts#T1107 - File deletion
Avatar photo
Detecteam
X

Detecteam is transforming cybersecurity detection from static rule-writing to autonomous, continuous validation. Our REFLEX platform automates the detection lifecycle—building, testing, validating and deploying detections in minutes, not months. We help enterprises maximize ROI on existing tools, close high-risk detection gaps faster, and scale security outcomes without scaling headcount. This is the future of detection-as-code, and we’re leading it.

CONTACT US

Detecteam Inc.
300 Lenora Street PMB 659
Seattle, WA 98121 USA
+1 (650) 542-0831
sales@detecteam.com

  • Privacy Policy

SOCIAL MEDIA

Twitter Linkedin
OUR NEWSLETTER

Check your inbox or spam to confirm your subscription.

© 2025 Detecteam Inc. All Rights Reserved.

  • Company
    • Founders Story
    • The Team
  • Product
    • About Us
  • Solutions
    • Use Cases
  • Resources
    • Detecteam Blogs
    • Contact Us
Search