Cybersecurity researchers have identified a new cryptominer malware that targets both Windows and Linux computers. The malware, called Golang, aims to mine Monero, an open-source cryptocurrency created in 2014, according to US-based company Barracuda Networks.

While the volume is still low, researchers have identified seven IP addresses linked to this new malware variant so far – all based in China.
Researchers observed that the "Golang" malware focuses on attacking web application frameworks, application servers, and non-HTTP services such as Redis and MSSQL, rather than targeting end-users.
“Hackers are once again turning to Golang, as it is not typically detected by antivirus. While it targets vulnerable servers, it remains one of the top threat actors that cybercriminals ,” said Fleming Shi, CTO of Barracuda Networks.
Once the Golang malware infects a computer, it downloads files based on the platform it is attacking. For Windows computers, the malware also adds a user backdoor.
Organizations should have a web application firewall in place and properly configured as the new Golang malware spreads by scanning the internet for vulnerable machines.
If organizations know how this malware variant operates, it can help them monitor Windows and Linux servers in case any such malicious activity occurs.
“We can defend organizations from this malware by monitoring endpoints for suspicious activity, as well as increased usage , which is associated with most cryptominers,” Shi said.
Additional information regarding the above news has not been released so far, with the news not being confirmed by SecNews. The article will be updated with additional information if the above is confirmed.
