New Golang-Based Malware Dubbed Titan Stealer

“One of the primary reasons [threat actors] may be using Golang for their information stealer malware is because it allows them to easily create cross-platform malware that can run on multiple operating systems, such as Windows, Linux, and macOS. Additionally, the Go compiled binary files are small in size, making them more difficult to detect by security software,” reads Cyble’s technical analysis. The finding comes a little more than two months after SEKOIA announced Aurora Stealer, another Go-based malware that is being used by several malicious actors in their campaigns. The malware often spreads through websites that imitate well-known software, with the same domains being continuously updated to host trojanized versions of various applications. To avoid being detected by antivirus software, it has also been seen using a technique called padding to artificially inflate the size of the executables to as much as 260MB by adding random data. The discoveries follow a malware operation that was seen spreading Raccoon and Vidar using many fraudulent websites masquerading as legitimate programs.

https://thehackernews.com/2023/01/titan-stealer-new-golang-based.html