Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (2,582)
  • Analysis (2,729)
  • Bitcoin (3,337)
  • Blockchain (2,037)
  • DeFi (2,449)
  • Ethereum (2,326)
  • Event (94)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (2,511)
  • Press Releases (10)
  • Reddit (2,008)
  • Regulation (2,330)
  • Security (3,207)
  • Thought Leadership (3)
  • Videos (43)
Hand picked
  • North Koreans Hackers Stealing Crypto with Fake Zoom Calls – BFM Times
  • Zcash Price Falls as Developer Activity Hits Multi-Year Low
  • Grayscale Files for Spot BNB ETF, Will BNB Price Go Above $1,000?
  • Analyst Lays Out the Bullish Case for XRP and Why the Price Will Hit an All-Time High Soon
  • FinFusion Exchange advances global system architecture optimization, clarifying operational and compliance structure
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»Blockchain»New GoBruteforcer attack wave targets crypto and blockchain projects
Blockchain

New GoBruteforcer attack wave targets crypto and blockchain projects

January 10, 2026No Comments
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


New GoBruteforcer attack wave targets crypto and blockchain projects

A new wave of GoBruteforcer botnet malware attacks targets cryptocurrency and blockchain project databases on exposed servers allegedly configured using AI-generated examples.

GoBrutforcer is also known as GoBrut. It is a Golang-based botnet that typically targets exposed FTP, MySQL, PostgreSQL, and phpMyAdmin services.

The malware often relies on compromised Linux servers to scan random public IP addresses and carry out brute force login attacks.

Ace

Tackle weak defenses

Check Point researchers estimate that there are more than 50,000 Internet servers that could be vulnerable to GoBrut attacks.

They say the initial compromise is often achieved via FTP servers on servers running XAMPP, because the setup often has a weak default password unless the administrator goes through the security setup.

“When attackers gain access to XAMPP FTP using a standard account (usually demon Or person) and a weak default password, the next step is usually to download a web shell into the web root,” Check Point

The attacker can download the web shell through other means, such as a misconfigured MySQL server or a phpMyAdmin panel. The infection chain continues with a downloader, fetching an IRC bot and the bruteforcer module.

Malware activity starts after a delay of 10 to 400 seconds, launching up to 95 brute force threads on x86_64 architectures, scanning random public IP address ranges, while ignoring private networks, AWS cloud ranges, and US government networks.

Each worker generates a single random public IPv4 address, probes the affected service port, goes through the provided list of credentials, and then exits. New workers are constantly generated to maintain the set level of competition.

The FTP module relies on a hard-coded list of 22 username-password pairs embedded directly in the binary. These credentials closely match the default or commonly deployed accounts in web hosting stacks like XAMPP.

Chain of infection
GoBruteforcer infection chain
Source: Checkpoint

Check Point reports that in recent campaigns, GoBruteforcer activity is fueled by the reuse of common server configuration snippets generated by large language models (LLMs), leading to a proliferation of weak and predictable default usernames, such as application user, myuserAnd operator.

These usernames frequently appear in AI-generated Docker and DevOps instructions, leading researchers to believe that the configurations were added to real-world systems, making them vulnerable to password spraying attacks.

The second trend fueling the botnet’s recent campaign is outdated server stacks like XAMPP that continue to ship with default credentials and open FTP services. These deployments expose vulnerable Webroot directories, allowing attackers to remove web shells.

Check Point’s report highlights a campaign in which a compromised host was infected by TRON wallet scanning tools that perform scans on TRON and Binance Smart Chain (BSC). The attackers used a file containing approximately 23,000 TRON addresses, targeting them with automated utilities to identify and empty wallets with non-zero balances.

Administrators defending against GoBruteforcer should avoid using AI-generated deployment guides and rely on non-default usernames with strong, unique passwords.

It is also recommended to check FTP, phpMyAdmin, MySQL and PostgreSQL for exposed services and replace outdated software stacks like XAMPP with more secure alternatives.

Ace

Whether you want to clean up old keys or set guardrails for AI-generated code, this guide helps your team build securely from the start.

Get the cheat sheet and take the guesswork out of managing secrets.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThe new BlackRock report exposes a historic shift in crypto that leaves only a single blockchain controlling the settlement layer.
Next Article Reviewing DeFi NEOE DEFI Technologies Narrative After Target Reset and DeFi Alpha Delays

Related Posts

Blockchain

Financial TimesLloyds is leading the charge in using blockchain to disrupt the UK banking industry. Charlie Nunn is on a mission to tear up the UK mortgage market. The managing director of Lloyds Banking Group, the largest in the country….2 days ago

January 10, 2026
Blockchain

JP Morgan’s Kinexys to integrate token into Canton blockchain

January 10, 2026
Blockchain

24/7 Global Stock Market Is Impossible on Today’s Blockchain — TradingView News

January 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Single Page Post
Share
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Featured Content
Event

Black Swan Summit India to Drive the Future of India’s Digital Finance Economy

January 8, 2026

The Black Swan Summit India, held under the theme “Reshaping India’s Digital Finance Economy: Employment,…

Event

WikiEXPO Hong Kong 2026 to Unite Global Fintech, Forex, TradFi, and Crypto Leaders

January 7, 2026

WikiEXPO Hong Kong 2026, Asia’s largest Fintech, Forex, TradFi, and Crypto carnival, will take place on July 23–24,…

1 2 3 … 69 Next
  • Facebook
  • Twitter
  • Instagram
  • YouTube

Grayscale Files for Spot BNB ETF, Will BNB Price Go Above $1,000?

January 11, 2026

Chainlink – Will Nasdaq CME News Push LINK Price to $15 Again?

January 10, 2026

Coinbase Adds Two Solana Altcoins and Two Core Ecosystem Coins to Listing Roadmap

January 10, 2026
Facebook X (Twitter) Instagram LinkedIn
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
© 2026 Altcoin Observer. all rights reserved by Tech Team.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 90,673.00
ethereum
Ethereum (ETH) $ 3,095.28
tether
Tether (USDT) $ 0.998868
xrp
XRP (XRP) $ 2.09
bnb
BNB (BNB) $ 912.29
usd-coin
USDC (USDC) $ 1.00
tron
TRON (TRX) $ 0.300145
staked-ether
Lido Staked Ether (STETH) $ 3,094.82
dogecoin
Dogecoin (DOGE) $ 0.13932
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.00