Summary
Threat details
GoldBrute will identify target servers by scanning random IP addresses, with each identified target sent back to a single command and control server via an AES encrypted WebSocket connection. Once it has discovered 80 potential targets, GoldBrute will then begin it's brute-force phase. Each individual GoldBrute bot will only attempt one username and passcode combination per target, likely in an effort to reduce detection as every authentication attempt will originate from a different IP address. Any successful attempt will result in GoldBrute downloading and extracting a ZIP archive containing itself to the affected server.
At the time of publication, it is unclear what the GoldBrute botnet's purpose is beyond its own growth.
Remediation steps
| Type | Step |
|---|---|
|
If RDP is not used, then ensure port 3389 (TCP/UDP) is blocked at your internet firewall. If RDP is used, then:
Additionally, to prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:44 pm