wincfg: Go-Based Stealer Payload
wincfg is a Go-based stealer payload used in the StubMaker campaign. It extracts credentials from Chromium-based browsers, collects cryptocurrency wallets and seed…
wincfg is a Go-based stealer payload used in the StubMaker campaign. It extracts credentials from Chromium-based browsers, collects cryptocurrency wallets and seed…
Go-based remote access trojan delivered via fake updates in the CaptiveCrunch campaign. It captures screenshots, steals credentials, and provides remote shell access.
A compiled Go ransomware designed to encrypt AI model files, vector indexes, and training datasets. Uses AES-256-CTR with RSA-2048 key wrapping. Targets…
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator first documented earlier this…
Caeruleus is a free open-source toolkit from Praetorian that consolidates Bluetooth Low Energy testing into a single Go binary. It supports scanning,…
FlockWiper is a multi-pass wiper that overwrites the Windows drive with different data patterns. It was rewritten in Go for GigaWiper and…
Lambsys is a Go-based ELF executable used in cryptojacking campaigns targeting Langflow vulnerabilities. It terminates rival miners, disables security controls, establishes persistence,…
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages designed to deploy a Python-based information stealer on…
A cluster of malicious packages that use fake .woff2 font files to conceal JavaScript payloads. Tactically overlaps with TaskJacker and PolinRider, using…
Nextron Systems discovered 16 Go packages containing the same malware as the npm packages, targeting the Go ecosystem with a Python infostealer.