Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Madonna features surprise star in Sabrina Carpenter’s ‘Bring Your Love’ video

Discover the Digital Twin That Revolutionizes Online Sales: The Story of Farmasi and a Collaborator Who Changes Everything

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Malicious GO modules pose as SSH brute force tool and steal credentials via Telegram bot
Celebrities

Malicious GO modules pose as SSH brute force tool and steal credentials via Telegram bot

By August 24, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

August 24, 2025Ravi LakshmananMalware/Supply Chain Security

SSH Brute Force Tool

Cybersecurity researchers have discovered a malicious GO module that presents its status as a brute force tool for SSH, but in reality it includes the ability to carefully remove credentials from its creators.

“In the first successful login, the package sends the target IP address, username and password to a hard-coded telegram bot controlled by the threat actor,” said Socket researcher Kirill Boychenko.

The deceptive package named “Golang-Random-IP-Ssh-Bruteforce” is linked to a Github account called Illdieanyway (G3TT) that is currently inaccessible. However, it is still available at Pkg.go[.]Developer. It was released on June 24th, 2022.

The software supply chain security company said the GO module works by scanning random IPv4 addresses of publicly available SSH services on TCP port 22, brute-force the service using a built-in username password list, and removing successful credentials to the attacker.

A notable aspect of malware is that by setting “ssh.insecureignorehostkey” as Hostkeycallback, it intentionally disables host key verification, which allows the SSH client to accept connections from any server, regardless of identity.

WordList is fairly simple, with only two username routes and an admin. It also pairs weak passwords such as root, test, password, administrator, 12345678, 1234, QWERTY, WebAdmin, Webmaster, TechSupport, LetMein, PassW@rd.

Identity Security Risk Assessment

The malicious code runs in an infinite loop to generate an IPv4 address, and the package attempts simultaneous SSH logins from the WordList.

Details will be sent via the API to a threat actor controlled telegram bot named “@sshzxc_bot” (ssh_bot) to allow for the receipt of credentials. The message is sent to the account via the bot using the handle “@io_ping” (gett).

SSH Brute Force Tool

The currently deleted Internet archive snapshots of GitHub accounts show that G3TT’s software portfolio (also known as G3TT’s software portfolio) includes an IP port scanner, Instagram profile information and media parser, as well as a PHP-based command and control (C2) botnet called SELICA-C2.

Their YouTube channel remains accessible and hosts a variety of short form videos that they claim to be “how to hack a Telegram Bot” and “the most powerful SMS bomber in the Russian Federation.” The threat leader is rated as Russian origin.

“This package infers scans and password guesses to unconscious operators, spreads risks across the IPS, and leaks success to a single threat actor-controlled telegram bot,” says Boychenko.

“Disables host key verification, drives high concurrency after the first enabled login, and prioritizes quick capture. As TelegramBotAPI uses HTTPS, traffic looks like a normal web request and can pass through coarse output controls.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleNASA’s patient rover spies on Mars with a mysterious “helmet” (Photo)
Next Article iPhone 17, “the thinnest iPhone ever” and everything else we expect from Apple’s hardware events

Related Posts

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Madonna features surprise star in Sabrina Carpenter’s ‘Bring Your Love’ video

Discover the Digital Twin That Revolutionizes Online Sales: The Story of Farmasi and a Collaborator Who Changes Everything

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

Ariana Grande’s “Petal” tracklist released one song at a time on tour

Trending Posts

Madonna features surprise star in Sabrina Carpenter’s ‘Bring Your Love’ video

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Ariana Grande’s “Petal” tracklist released one song at a time on tour

June 15, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.