TI Mindmap HUB
Threat Intelligence Report

Malicious Go “crypto” Module Steals Passwords and Deploys Rekoobe Backdoor

📅 February 28, 2026 📰 socket.dev 🔍 0 CVE(s) referenced

A malicious Go module impersonating the widely trusted golang.org/x/crypto library covertly harvests passwords, exfiltrates them, and deploys a multi-stage Linux backdoor chain—including the Rekoobe backdoor—via supply chain compromise, demonstrating the severe risks posed by dependency impersonation in open source ecosystems.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle