GadgetBond

  • Latest
  • How-to
  • Tech
    • AI
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Add GadgetBond as a preferred source to see more of our stories on Google.
Font ResizerAa
GadgetBondGadgetBond
  • Latest
  • Tech
  • AI
  • Deals
  • How-to
  • Apps
  • Mobile
  • Gaming
  • Streaming
  • Transportation
Search
  • Latest
  • Deals
  • How-to
  • Tech
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • AI
    • Anthropic
    • ChatGPT
    • ChatGPT Atlas
    • Gemini AI (formerly Bard)
    • Google DeepMind
    • Grok AI
    • Meta AI
    • Microsoft Copilot
    • OpenAI
    • Perplexity
    • xAI
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Follow US
Tech

AT&T Alien Labs discovers new Golang malware (BotenaGo) with over 30 exploits that target millions of routers and IoT devices

By
Shubham Sawarkar
Shubham Sawarkar's avatar
ByShubham Sawarkar
Editor-in-Chief
I’m a tech enthusiast who loves exploring gadgets, trends, and innovations. With certifications in CISCO Routing & Switching and Windows Server Administration, I bring a sharp...
Follow:
- Editor-in-Chief
Nov 20, 2021, 7:43 PM EST
Share
We may get a commission from retail offers. Learn more
AT&T Alien Labs discovers new Golang malware (BotenaGo) with over 30 exploits that target millions of routers and IoT devices
SHARE

According to AT&T Alien Labs, malware written in the open-source programming language Golang could attack millions of routers and IoT devices.

BotenaGo is a malware that can attack a target with over 30 different exploit functionalities. It deploys a backdoor and waits for a target to be sent to it via port 19412 from a remote operator or from another related module running on the same machine. According to AT&T, the malware’s actor and the number of compromised devices are still unknown.

Golang, usually known as Go, is a Google-designed open-source programming language that was initially released in 2007 to make it easier for developers to create software. According to recent Intezer research, the Go programming language has risen in popularity among malware creators considerably in recent years. According to the site, there has been a 2000% boost in malware code written in Go that has been discovered in the wild.

The ease with which attackers may compile the same code for different platforms, making it easier for them to distribute malware across multiple operating systems, is one of the reasons for its increased popularity.

According to AT&T Alien Labs security researcher Ofer Caspi, BotenaGo currently has a low antivirus (AV) detection rate, with only 6/62 known AVs seen in VirusTotal.

Some anti-virus software recognizes these new malware types as Mirai malware because the payload connections are identical. However, there are differences between the Mirai malware and the new Go malware variants, including changes in programming languages and malware structures. Mirai is a botnet that communicates with its command and control (C&C). It also has several DDoS capabilities.

The malware strains uncovered by Alien Labs don’t have the same attack capabilities as Mirai malware, and they just hunt for weak systems to transmit the payload. Furthermore, Mirai employs an XOR table to store its strings and other data, as well as to decrypt them when necessary; this is not the case with the new Go malware. As a result, Alien Labs feels this danger is novel and has given it the moniker BotenaGo.

The BotenaGo malware begins by setting up global infection counters, which will be displayed on the screen and alert the hacker of the overall number of successful infections. It then looks in the dlrs folder for shell script files to load. The infection will stop and quit at this stage if the dlrs folder is missing.

The malware then launches a function that starts the malware attack surface by mapping all offensive functions to the relevant string that represents the targeted system. This is the final and most crucial preparation. Each function is associated with a string that represents a possible target system, such as a signature.

To deliver its exploit, the malware sends a simple GET request to the target. The delivered data from the GET request is then compared against each system signature that has been mapped to attack methods.

A search on Shodan yields around 250,000 devices that could be targeted by this function. The malware starts 33 exploit functions in total, all of which are ready to infect potential victims.

BotenaGo’s payload is remote shell commands that will be executed on devices where the vulnerability has been successfully exploited. The malware uses several links, each with a different payload, depending on the affected PC. Because the attackers had removed all of the payloads from the hosted servers at the time of analysis, Alien Labs was unable to evaluate any of them.

BotenaGo has no active connection with its C&C, which raises concerns about how it functions. Alien Labs has a few ideas on how the malware works and how it gets a target to attack.

Alien Labs advises companies to maintain their software up to date with security patches, limit internet access on Linux servers and IoT devices, and use a properly configured firewall. Network traffic, outbound port scans, and excessive bandwidth usage should all be monitored by users.

“Malware authors continue to create new techniques for writing malware and upgrading its capabilities,” said Caspi. “In this case, new malware writing in Golang – which Alien Labs has named BotenaGo – can run as a botnet on different OS platforms with small modifications.”


Discover more from GadgetBond

Subscribe to get the latest posts sent to your email.

Topic:AT&T
Leave a Comment

Leave a ReplyCancel reply

Most Popular

Apple’s iPhone 18 plan is changing

Snap’s new SPECS AR glasses are real, pricey, and coming this fall

iOS 27: Apple Wallet keys now support Disney World

Sign in with Apple and Hide My Email are getting a shared domain

Perplexity launches Brain for its Computer agent

Under-16s face social media ban in the UK

Here’s how to reset your Mac login password in a few steps

Rec League is the kind of app the internet has been missing

Perplexity Computer comes to Comet on iPhone

Apple’s new private.icloud.com domain has a downside

Also Read
Apple iPhone 17 Pro JerryRigEverything durability test

Apple’s next Pro iPhone may not solve the scratch problem

A group of contestants covered in mud celebrate with a team hug on a beach challenge course in Survivor. The castaways smile, cheer, and embrace one another after completing a competition, with the ocean visible in the background and a colorful tribal-themed challenge marker in the foreground. The image captures the camaraderie, endurance, and emotional highs that define the long-running reality competition series on Paramount+.

What to watch on Paramount+ right now

Illustrated graphic representing online journalism and digital publishing. A blue vintage-style typewriter prints a webpage-like document featuring text lines and social media icons, while a browser search bar extends from the side. Set against a dark textured background, the artwork symbolizes the intersection of traditional journalism, web publishing, search, and social media in the digital news era.

Before the web, there was print

Promotional image for the Hypelist app featuring a collection of Polaroid-style photographs scattered across a black background. The photos capture a variety of everyday moments, including a seaside meal, a coffee table scene, a ferry cabin, cyclists riding at night, landscapes, and lifestyle snapshots. The collage-style layout highlights Hypelist’s focus on creating, organizing, and sharing visual collections, recommendations, and personal lists based on experiences, places, and interests.

Hypelist lets you build lists around the things you love

Promotional image for the Swipewipe photo cleaner app showing three versions of the same portrait photo arranged on a soft beige background. The center image is highlighted with a green checkmark to indicate a photo being kept, while the smaller images on either side feature trash can icons, representing photos selected for deletion. The visual illustrates Swipewipe’s swipe-based photo organization and cleanup process for managing duplicate or unwanted images.

Swipewipe makes clearing your camera roll feel oddly easy

The Apple Music logo in white text against a vibrant red background. The text has a slight distortion or wave effect, giving it a dynamic, musical appearance. The Apple logo precedes the word "Music" and both share the same rippling, audiographic style treatment.

Apple Music iOS 27 update: AutoMix, artist pages, and Siri AI

Soccer player Antonee Robinson stands backstage at a sporting event wearing a black team jacket and an accreditation badge while using a pair of unreleased over-ear Beats headphones. The headphones feature a white exterior with dark blue ear cushions and a minimalist Beats logo on the ear cup. Other team members wearing wireless earbuds can be seen in the background as the group prepares to enter the venue.

The new Beats headphones, Antonee Robinson just teased on his way to the World Cup

Promotional banner for Xbox Game Pass Ultimate showcasing a lineup of popular games across multiple genres. The artwork features an anime-style character, an American football player, an adventurer in a fedora, a futuristic armored soldier, and a block-based fantasy game scene. The Xbox logo and "Game Pass Ultimate" branding are displayed prominently in the center, emphasizing access to a wide catalog of console, PC, and cloud gaming titles through a single subscription.

Xbox Game Pass Ultimate: pricing, perks, and how it all fits together

Company Info
  • Homepage
  • Support my work
  • Latest stories
  • Company updates
  • GDB Recommends
  • Daily newsletters
  • About us
  • Contact us
  • Write for us
  • Editorial guidelines
Legal
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • DMCA
  • Disclaimer
  • Accessibility Policy
  • Security Policy
  • Do Not Sell or Share My Personal Information
Socials
Follow US

Disclosure: We love the products we feature and hope you’ll love them too. If you purchase through a link on our site, we may receive compensation at no additional cost to you. Read our ethics statement. Please note that pricing and availability are subject to change.

Copyright © 2026 GadgetBond. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | Do Not Sell/Share My Personal Information.