Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor
    Cybersecurity

    Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor

    adminBy adminFebruary 28, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Rekoobe Backdoor
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananFeb 27, 2026Malware / Linux Security

    Rekoobe Backdoor

    Cybersecurity researchers have disclosed details of a malicious Go module that’s designed to harvest passwords, create persistent access via SSH, and deliver a Linux backdoor named Rekoobe.

    The Go module, github[.]com/xinfeisoft/crypto, impersonates the legitimate “golang.org/x/crypto” codebase, but injects malicious code that’s responsible for exfiltrating secrets entered via terminal password prompts to a remote endpoint, fetches a shell script in response, and executes it.

    “This activity fits namespace confusion and impersonation of the legitimate golang.org/x/crypto subrepository (and its GitHub mirror github.com/golang/crypto),” Socket security researcher Kirill Boychenko said. “The legitimate project identifies go.googlesource.com/crypto as canonical and treats GitHub as a mirror, a distinction the threat actor abuses to make github.com/xinfeisoft/crypto look routine in dependency graphs.”

    Specifically, the backdoor has been placed within the “ssh/terminal/terminal.go” file, so that every time a victim application invokes ReadPassword() – a function supposedly meant to read input like passwords from a terminal – it causes those interactive secrets to be captured.

    The main responsibility of the downloaded script is to function as a Linux stager, appending a threat actor’s SSH key to the “/home/ubuntu/.ssh/authorized_keys” file, set iptables default policies to ACCEPT in an attempt to loosen firewall restrictions, and retrieve additional payloads from an external server while disguising them with the .mp5 extension.

    Of the two payloads, one is a helper that tests internet connectivity and attempts to communicate with an IP address (“154.84.63[.]184”) over TCP port 443. The program likely functions as a recon or loader, Socket noted.

    The second downloaded payload has been assessed to be Rekoobe, a known Linux trojan that has been detected in the wild since at least 2015. The backdoor is capable of receiving commands from an attacker-controlled server to download more payloads, steal files, and execute a reverse shell. As recently as August 2023, Rekoobe has been put to use by Chinese nation-state groups like APT31.

    While the package still remains listed on pkg.go.dev, the Go security team has taken steps to block the library as malicious.

    “This campaign will likely repeat because the pattern is low-effort and high-impact: a lookalike module that hooks a high-value boundary (ReadPassword), uses GitHub Raw as a rotating pointer, then pivots into curl | sh staging and Linux payload delivery,” Boychenko said.

    “Defenders should anticipate similar supply chain attacks targeting other ‘credential edge’ libraries (SSH helpers, CLI auth prompts, database connectors) and more indirection through hosting surfaces to rotate infrastructure without republishing code.”

    backdoor Crypto Deploys Malicious Module Passwords Rekoobe Steals
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleThe new Honor Magic 8 Pro Photography Kit is changing my expectations for smartphone camera quality
    Next Article Signal Private Messenger 8.1.2 beta APK Download by Signal Foundation
    admin
    • Website

    Related Posts

    DDR5 Bot Scalping, Samsung TV Tracking, Reddit Privacy Fine & More

    March 5, 2026

    Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilities

    March 5, 2026

    Police dismantles online gambling ring exploiting Ukrainian women

    March 5, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    DDR5 Bot Scalping, Samsung TV Tracking, Reddit Privacy Fine & More

    March 5, 2026

    A Survey of 1,000+ US Consumers

    March 5, 2026

    I finally upgraded to a mesh Wi-Fi system and it made me realize Wi-Fi extenders are a scam

    March 5, 2026

    Lack of regulatory action on hyperscaler dominance prompts inquiry chair to quit

    March 5, 2026
    Categories
    • Blogging (33)
    • Cybersecurity (616)
    • Privacy & Online Earning (92)
    • SEO & Digital Marketing (390)
    • Tech Tools & Mobile / Apps (754)
    • WiFi / Internet & Networking (110)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    DDR5 Bot Scalping, Samsung TV Tracking, Reddit Privacy Fine & More

    March 5, 2026

    A Survey of 1,000+ US Consumers

    March 5, 2026

    I finally upgraded to a mesh Wi-Fi system and it made me realize Wi-Fi extenders are a scam

    March 5, 2026
    Most Popular
    • DDR5 Bot Scalping, Samsung TV Tracking, Reddit Privacy Fine & More
    • A Survey of 1,000+ US Consumers
    • I finally upgraded to a mesh Wi-Fi system and it made me realize Wi-Fi extenders are a scam
    • Lack of regulatory action on hyperscaler dominance prompts inquiry chair to quit
    • Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilities
    • The Government Uses Targeted Advertising to Track Your Location. Here’s What We Need to Do.
    • 4 Methods to Find Keywords Your Competitors Miss
    • My Samsung camera is infinitely better since I tweaked these settings
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.