BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GoBruteforcer Botnet Targets Crypto Projects with Bruteforce

GoBruteforcer targets crypto/blockchain servers—exploits weak defaults and AI-generated examples to brute-force databases and hunt TRON wallets.

  • GoBruteforcer operators are targeting crypto and blockchain project servers to add them to a botnet that brute-forces FTP, MySQL, PostgreSQL, and phpMyAdmin logins.
  • Campaigns exploit weak defaults and reused AI-generated deployment examples, plus exposed stacks like XAMPP, to gain initial access.
  • Compromised hosts run brute-force scans, serve payloads, and act as IRC-style control points; some probes search Tron addresses for non-zero balances.
  • Separate scanning activity has systematically probed misconfigured LLM endpoints, according to GreyNoise.

What: A new wave of attacks by GoBruteforcer targets database services on Linux servers to add them to a brute-force botnet.
Who: The activity was detailed by Check Point Research.
When/Where: Observations span mid-2025 through early 2026 on internet-exposed hosts.
Why: Operators exploit weak credentials and common defaults to harvest access and search for cryptocurrency funds.

- Advertisement -

Researchers trace the tool back to an initial report in 2023 and note the Malware evolved into a more obfuscated, cross-platform Golang IRC bot with improved persistence. The campaign uses a rotating list of usernames and reused weak passwords that often appear in tutorials and vendor examples, a feedstock amplified by AI-generated deployment snippets, according to Check Point Research.

Attackers frequently use exposed FTP on XAMPP servers as an entry point to upload a PHP web shell. The shell fetches an updated IRC bot tailored to the host architecture. Infected systems then (1) run brute-force modules against FTP, MySQL, Postgres, and phpMyAdmin, (2) host payloads for further compromise, and (3) operate as backup command-and-control nodes.

One staged module iterates TRON addresses via tronscanapi[.]com to find accounts with funds, indicating a focus on blockchain projects. GreyNoise separately reported methodical scans seeking misconfigured proxy servers that could expose commercial LLM APIs, including probes of providers such as OpenAI, Anthropic, and others.

“GoBruteforcer exemplifies a broader and persistent problem: The combination of exposed infrastructure, weak credentials, and increasingly automated tools,” researchers noted.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Microsoft Found Vulnerability in Anthropic’s Claude Code

Microsoft researchers discovered a Claude Code vulnerability where attack instructions in GitHub comments could...

OpenAI Launches ChatGPT ‘Lockdown Mode’ to Block Data Leaks

OpenAI has launched a new optional Lockdown Mode for ChatGPT personal accounts to mitigate...

SHIB Crashes to 2021 Price Levels, Sparking Investor Worry

Shiba Inu (SHIB) has fallen below $0.000005, a price level last seen in May...

Zcash Rallies 19% After Bug Fix; Founder: No Funds Stolen

ZCash (ZEC) surged 19% on June 6, sharply outperforming Bitcoin (BTC) after a major...

Smart TVs Co-opted Into AI Data-Scraping Network

A security researcher has reverse-engineered how a popular data firm turns consumer devices, including...

Must Read

The 10 Best Crypto Podcasts You Can’t Miss

Table of ContentsBest Cryptocurrency Podcasts To Add To Your Playing List1. The Money Movement2. The Crypto Conversation3. The Pomp Podcast4. What Bitcoin Did5. The...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading