Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor
好的,我现在需要帮用户总结一篇关于网络安全的文章,控制在100字以内。首先,我得通读整篇文章,抓住主要内容。 文章讲的是一个恶意的Go模块,它伪装成合法的代码库,用来窃取密码、创建SSH持久访问,并分发名为Rekoobe的Linux后门。这个模块隐藏在ssh/terminal文件中,每当应用调用ReadPassword()时,就会捕获密码信息。 然后,恶意脚本会添加SSH密钥到authorized_keys文件中,调整防火墙设置,并下载额外的payload。其中一个payload是Rekoobe,它能执行反向shell和窃取文件。这个模块已经被Go安全团队标记为恶意。 总结的时候要涵盖:恶意Go模块、伪装、窃取密码、创建SSH访问、分发Rekoobe后门。同时要简洁明了,不超过100字。 现在把这些点浓缩成一句话:一个恶意Go模块伪装成合法代码库,窃取密码并创建SSH访问权限,分发Linux后门Rekoobe。确保语言流畅自然。 </think> 一个恶意Go模块伪装成合法代码库以窃取密码并创建SSH访问权限,最终分发Linux后门Rekoobe。 2026-2-27 15:33:0 Author: thehackernews.com(查看原文) 阅读量:4 收藏

Rekoobe Backdoor

Cybersecurity researchers have disclosed details of a malicious Go module that's designed to harvest passwords, create persistent access via SSH, and deliver a Linux backdoor named Rekoobe.

The Go module, github[.]com/xinfeisoft/crypto, impersonates the legitimate "golang.org/x/crypto" codebase, but injects malicious code that's responsible for exfiltrating secrets entered via terminal password prompts to a remote endpoint, fetches a shell script in response, and executes it.

"This activity fits namespace confusion and impersonation of the legitimate golang.org/x/crypto subrepository (and its GitHub mirror github.com/golang/crypto)," Socket security researcher Kirill Boychenko said. "The legitimate project identifies go.googlesource.com/crypto as canonical and treats GitHub as a mirror, a distinction the threat actor abuses to make github.com/xinfeisoft/crypto look routine in dependency graphs."

Specifically, the backdoor has been placed within the "ssh/terminal/terminal.go" file, so that every time a victim application invokes ReadPassword() – a function supposedly meant to read input like passwords from a terminal – it causes that information to capture interactive secrets.

The main responsibility of the downloaded script is to function as a Linux stager, appending a threat actor's SSH key to the "/home/ubuntu/.ssh/authorized_keys" file, set iptables default policies to ACCEPT in an attempt to loosen firewall restrictions, and retrieve additional payloads from an external server while disguising them with the .mp5 extension.

Of the two payloads, one is a helper that tests internet connectivity and attempts to communicate with an IP address ("154.84.63[.]184") over TCP port 443. The program likely functions as a recon or loader, Socket noted.

The second downloaded payload has been assessed to be Rekoobe, a known Linux trojan that has been detected in the wild since at least 2015. The backdoor is capable of receiving commands from an attacker-controlled server to download more payloads, steal files, and execute a reverse shell. As recently as August 2023, Rekoobe has been put to use by Chinese nation-state groups like APT31.

While the package still remains listed on pkg.go.dev, the Go security team has taken steps to block the package as malicious.

"This campaign will likely repeat because the pattern is low-effort and high-impact: a lookalike module that hooks a high-value boundary (ReadPassword), uses GitHub Raw as a rotating pointer, then pivots into curl | sh staging and Linux payload delivery," Boychenko said.

"Defenders should anticipate similar supply chain attacks targeting other 'credential edge' libraries (SSH helpers, CLI auth prompts, database connectors) and more indirection through hosting surfaces to rotate infrastructure without republishing code."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/02/malicious-go-crypto-module-steals.html
如有侵权请联系:admin#unsafe.sh