Cybersecurity researchers have discovered a malicious Go module that presents itself as a brute-force tool for SSH, but actually contains functionality to secretly extract credentials.

"Upon the first successful connection, the packet sends the target's IP address, username, and password to a hard-coded Telegram bot controlled by the threat actor," said Socket researcher Kirill Boychenko.
The deceptive package, named “golang-random-ip-ssh-bruteforce”, has been linked to a GitHub account called IllDieAnyway (G3TT), which is no longer accessible. However, it is still available at pkg.go[.]dev (published on June 24, 2022).
See also: New Android malware mimics Russian FSB antivirus
The security firm said the malicious Go module works by scanning random IPv4 addresses for services SSHIt then attempts to brute-force the service using a built-in list of usernames and passwords and extracts the credentials to send to the attacker.
A notable element of the malware is that it intentionally disables host key verification by setting “ssh.InsecureIgnoreHostKey” as the HostKeyCallback, thus allowing the SSH client to accept connections from any server, regardless of its identity.
The wordlist is quite simple, including only two usernames (root and admin) and combining them with weak passwords such as: root, test, password, admin, 12345678, 1234, qwerty, webadmin, webmaster, techsupport, letmein, Passw@rd.
The malicious code runs in an infinite loop to generate IPv4 addresses, with the package attempting simultaneous SSH connections from the wordlist.

The details are passed to a Telegram bot, named “@sshZXC_bot” (ssh_bot), controlled by the attacker via an API. This then confirms receipt of the credentials. Messages are sent via the bot to an account with the handle “@io_ping” (Gett).
See also: QuirkyLoader helps distribute infostealer malware
An Internet Archive screenshot from the now-deleted GitHub account shows that IllDieAnyway's software portfolio included an IP port scanner, an Instagram profile information and media parser, and a command-and-control (C2) botnet (named Selica-C2).
His YouTube channel, which remains accessible, hosts several short videos on “How to hack a Telegram bot” and what he claims is the “most powerful SMS bomber for the Russian Federation,” which can send mass SMS spam and messages to VK users using a Telegram bot. The attacker is believed to be of Russian origin.
Malicious Go Module: Significant Threat
This case clearly shows how attackers leverage the open source software to trick not only targets, but also other would-be “hackers” into thinking they are using a tool for attacks. Here, the malicious Go module becomes “bait”: it does not limit itself to brute-force, but collects and sends the sensitive information itself to its creator.
This tactic highlights that even illegitimate users can fall victim – an ironic reminder that trusting unknown code is dangerous regardless of the motivation for use. The choice to use Telegram as a C2 channel demonstrates a trend we are seeing more and more often: transferring data through legitimate platforms that offer encryption and high availability.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Misusing Microsoft Help Index Files to execute PipeMagic malware

This makes it harder for authorities to track down the activity, as the data looks like “legitimate” traffic in a widely used app. Although the list of passwords is simplistic, it shows that attacks are still based on human negligence: weak passwords like “12345678” or “admin” are still in use. The fact that such a poor wordlist is enough to justify the development of such a tool is an indication of how far behind basic digital hygiene still lies on many servers.
Finally, the existence of other projects by the same creator – from botnets to SMS bombers – underlines that we are not talking about an isolated incident but about an entire small-scale “industry” that produces malicious tools. For cybersecurity experts, such discoveries act as a wake-up call: stricter supervision of software repositories is needed, as well as training for administrators so that they do not rest on the use of default passwords or disabling critical security mechanisms.
