BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious Go SSH Tool Steals Credentials Via Telegram Bot Alert

Fake Go SSH Tool Steals Credentials via Telegram Instead of Brute-Forcing Servers

  • Researchers found a fake Go module that steals SSH credentials instead of providing legitimate brute-force functionality.
  • The malicious module sends stolen logins to a Telegram bot once a successful SSH login occurs.
  • The tool’s wordlist targets common usernames and weak passwords on random IPv4 SSH servers.
  • The campaign is linked to the now-inaccessible IllDieAnyway GitHub account, but the module remains available online.
  • The exfiltration method uses encrypted Telegram traffic, helping attackers avoid basic egress monitoring.

Cybersecurity researchers reported finding a Go programming module that pretends to be a brute-force tool for SSH logins but is designed to secretly collect and transmit stolen credentials to the module’s creator. The tool, named “golang-random-ip-ssh-bruteforce,” first appeared on June 24, 2022, and remains available on the software repository pkg.go[.]dev.

- Advertisement -

According to researchers at Socket, the module scans random public IPv4 addresses on TCP port 22 to find SSH servers, then tries logging in using a small list of common usernames and passwords. When a login attempt succeeds, the tool immediately exfiltrates the server’s IP address, username, and password to a hard-coded Telegram bot managed by the attacker. “On the first successful login, the package sends the target IP address, username, and password to a hard-coded Telegram bot controlled by the threat actor,” researcher Kirill Boychenko stated.

The username list only includes “root” and “admin,” while the passwords are common weak choices such as “admin,” “12345678,” “password,” and similar. The module disables host key verification by using the “ssh.InsecureIgnoreHostKey” callback, allowing it to accept connections from any SSH server even if its identity is unknown. The tool operates in an infinite loop, repeatedly generating new IP addresses and attempting concurrent logins with the preset credentials.

Messages with stolen credentials are sent through Telegram’s API to an account labeled “@io_ping” (Gett), using a recipient bot called “@sshZXC_bot” (ssh_bot). Researchers say the activity traces back to the IllDieAnyway (G3TT) GitHub account, which also hosted Hacking tools like an IP port scanner and a PHP command-and-control botnet called Selica-C2. While the GitHub account is now offline, historical snapshots and a YouTube channel remain accessible, showing the creator sharing hacking-related content in Russian.

Socket noted that the tool uses the scanning operators’ own internet addresses, distributing risk away from the original threat actor. The Telegram channel uses regular HTTPS traffic, which can make these exfiltrations appear like normal web use and avoid detection by standard network filters.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

StubMaker: 16 typosquat RubyGems packages steal data

Cybersecurity researchers have discovered a new typosquatting campaign, tracked as StubMaker, targeting RubyGems users...

Gold Slips 0.4% to $4,397 on Rising Yields, Oil

Gold prices fell 0.4% today, August 18, 2026, amid rising US Treasury yields and...

Ethereum Warns Tools May Break With Glamsterdam Gas Model Upgrade

The Ethereum Foundation warns that wallets, indexers, and gas estimators may break due to...

Kraken parent Payward uses Claude Mythos AI for security

Kraken parent Payward has joined Anthropic's Project Glasswing, using Claude Mythos 5 for Cybersecurity...

Anthropic revenue run rate surges past $65B, outpacing OpenAI

Anthropic's annualized revenue run rate surged past $65 billion in late July, a sevenfold...

Must Read

12 Hosting Providers To Buy VPS With Bitcoin: An Expert Guide for 2026

You need a VPS. You want to pay with Bitcoin. Simple enough, right?Not quite. The market for crypto VPS = VPS hosting that accepts...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading