
It seems that the GoLang programming language is particularly popular when it comes to creating malware . This is mainly because it provides many benefits to criminals , since it allows them to infiltrate their victims' systems unnoticed
In July 2019, a security researcher discovered approximately 10,700 unique malware samples written in the Go programming language, also known as GoLang.
Why do hackers choose GoLang?
The features of this programming language provide cybercriminals exactly what they seek: to infiltrate the systems they target without being detected.
This language can create a single base code for all major operating systems. Malware written in GoLang has large sizes. This allows them to penetrate systems without being detected, as some antivirus programs cannot detect large files.
Additionally it provides a rich «library ecosystem», which makes the process of creating malicious software quite smooth.
Recent use cases of this programming language
A trojan that targeted e-commerce websites using brute force attacks was detected in February 2019 and was written in GoLang.
The JCry, which had infected various systems as part of a coordinated cyberattack and targeted several Israeli websites, was also written in the same programming language.
Security researchers discovered July, a cryptomining campaign that spread the malicious GoLang software, targeting Linux servers.
Also in July, users in South Korea were hit by a campaign that distributed malware called GoBotKR, written in GoLang. It was spread via torrent sites and allowed attackers to control an infected system remotely.
Finally, the most recent case concerns the Fancy Bear, which returned in September with an updated malicious campaign. The updates include a payload written in the aforementioned language and the introduction of a new GoLang backdoor.
It is therefore clear that GoLang is gaining increasing popularity among hackers who develop malicious software for cybercrime.
