QUICAgent: Go-Based Backdoor
QUICAgent is a Golang-based backdoor used in Operation QUICSILVER. It employs sandbox evasion, communicates via QUIC over UDP port 443, and supports…
QUICAgent is a Golang-based backdoor used in Operation QUICSILVER. It employs sandbox evasion, communicates via QUIC over UDP port 443, and supports…
CornFlake RAT is a Go-based remote access trojan deployed via adversary-in-the-middle (AitM) attacks, often disguised as browser or OS updates. It performs…
GoginRAT is a Go-based remote access tool with architectural similarities to NomadRAT. It uses a separate transmitter for C2 and implements file…
wincfg is a Go-based stealer payload used in the StubMaker campaign. It extracts credentials from Chromium-based browsers, collects cryptocurrency wallets and seed…
Go-based remote access trojan delivered via fake updates in the CaptiveCrunch campaign. It captures screenshots, steals credentials, and provides remote shell access.
A compiled Go ransomware designed to encrypt AI model files, vector indexes, and training datasets. Uses AES-256-CTR with RSA-2048 key wrapping. Targets…
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator first documented earlier this…
Caeruleus is a free open-source toolkit from Praetorian that consolidates Bluetooth Low Energy testing into a single Go binary. It supports scanning,…
FlockWiper is a multi-pass wiper that overwrites the Windows drive with different data patterns. It was rewritten in Go for GigaWiper and…
Lambsys is a Go-based ELF executable used in cryptojacking campaigns targeting Langflow vulnerabilities. It terminates rival miners, disables security controls, establishes persistence,…