Hackers are targeting misconfigured servers running Apache Hadoop YARN, Docker, Confluence, or Redis with new Golang malware that automates the detection and attack of hosts.
See also: Malicious Google ads trick Mac users into installing Atomic Stealer malware

The malicious tools used in the campaign exploit configuration weaknesses and an old vulnerability in Atlassian Confluence to execute code on the computer.
Researchers at cloud forensics and incident response firm Cado Security discovered the Golang malware and analyzed the payloads used in attacks, in bash scripts and Golang ELF binaries.
Researchers note that the attack set is similar to previously reported cloud, some of which are attributed to threat actors such as TeamTNT, WatchDog, and Kiss-a-Dog.
The investigation began after receiving an initial alert about access to a Docker Engine API, with a new Alpine Linux-based container being created on the server.
For the next steps, the threat actor relies on multiple shell scripts and common Linux to install a cryptocurrency miner, establish persistent operation, and create a reverse shell.
See also: “TicTacToe Droppers” are used to distribute malware
New Golang malware for target identification
According to researchers, hackers are using a set of four innovative Golang malware payloads that are responsible for identifying and exploiting sockets running services for Hadoop YARN (h.sh), Docker (d.sh), Confluence (w.sh), and Redis (c.sh).

The payload names are probably a poor attempt to disguise them as bash scripts. However, they are 64-bit Golang ELF.
Hackers use Golang tools to scan a network segment for open ports 2375, 8088, 8090, or 6379, which are the default for the targets of this campaign.
In the case of “w.sh,” after discovering an IP address for a Confluence server, it discovers an exploit for CVE-2022-26134, a critical vulnerability that allows remote attackers to execute code without the need for authentication.
Another Golang malware vector is called “fkoths” and its mission is to remove traces of the original access by deleting Docker images from the Ubuntu or Alpine repositories.
Cado Security reported that the attacker used a larger shell file named “ar.sh” to proceed with the breach, prevent activity on the computer, and retrieve additional payloads, including the popular XMRig mining application for the Monero cryptocurrency.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: The possible existence of Chinese malware in US systems is a "time bomb"
How does malware affect digital security?
Malware, such as the Golang we mentioned above, is a significant threat to digital security. It can affect the security of digital systems in a variety of ways, including violating privacy, stealing data, corrupting files, and performing unwanted operations. One of the most common ways that malware affects digital security is through the theft of personal and confidential data. Malware can install itself on computer and steal information such as passwords, credit cards, or other sensitive data. In addition, it can cause significant damage to digital systems, destroying files or altering their functionality.
Source: bleepingcomputer
