Image for Article: Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor

Article Details

Title
Article: Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor
Impact Score
5 / 10
AI Summary (Processed Content)

A malicious Go module impersonates the legitimate "golang.org/x/crypto" library to steal passwords and deploy malware. It captures secrets entered via terminal prompts and executes a script that establishes persistent SSH access and retrieves additional payloads. One payload is the Rekoobe Linux backdoor, used by groups like APT31, which can execute commands, steal files, and create reverse shells. The main topics are a software supply chain attack using namespace confusion, the functionality of the malicious module and Rekoobe backdoor, and defensive warnings about similar future campaigns.

Original URL
https://thehackernews.com/2026/02/malicious-go-crypto-module-steals.html
Source Feed
The Hacker News
Published Date
2026-02-27 15:33
Fetched Date
2026-03-04 13:39
Processed Date
2026-03-04 13:58
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content