Threat Advisory

Graphalgo Malware Impacts DevOps Workstations Across Unauthorized Repositories

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Graphalgo malware has expanded into the Go ecosystem through malicious Terraform providers and Go Modules. The campaign involves gocommunity-io/dockerd, kreuzwenker/docker, gocommunity.io/orderedbtree, and gogets.dev/btreex, with the latter Terraform provider impersonating the legitimate kreuzwerker/docker package. The activity represents a targeted software supply-chain threat against developers and DevOps environments.

The malicious Terraform providers contain hidden execution paths that activate only when specific containerName and networkID values produce a predefined SHA256 hash. The resulting key decrypts an embedded archive whose files are subsequently executed as Go code. The Go module variants use similar techniques, including plaintext malware and payloads concealed inside files disguised as SQL content. A second-stage Go RAT collects system information such as the operating system, architecture, hostname, username, home directory, and Node.js availability. It uses encrypted Slack communications and an Ethereum smart contract as dual command-and-control channels, polling both sources for commands that can execute additional Go or JavaScript code or remove itself.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Graphalgo malware has expanded into the Go ecosystem through malicious Terraform providers and Go Modules. The campaign involves gocommunity-io/dockerd, kreuzwenker/docker, gocommunity.io/orderedbtree, and gogets.dev/btreex, with the latter Terraform provider impersonating the legitimate kreuzwerker/docker package. The activity represents a targeted software supply-chain threat against developers and DevOps environments.

The malicious Terraform providers contain hidden execution paths that activate only when specific containerName and networkID values produce a predefined SHA256 hash. The resulting key decrypts an embedded archive whose files are subsequently executed as Go code. The Go module variants use similar techniques, including plaintext malware and payloads concealed inside files disguised as SQL content. A second-stage Go RAT collects system information such as the operating system, architecture, hostname, username, home directory, and Node.js availability. It uses encrypted Slack communications and an Ethereum smart contract as dual command-and-control channels, polling both sources for commands that can execute additional Go or JavaScript code or remove itself.[emaillocker id="1283"]

The campaign demonstrates continued abuse of developer ecosystems to deliver malware through trusted package mechanisms. Fake Go ecosystem websites and forged repository commits are also used to increase package credibility and obscure the malware's history. Organizations should review Terraform providers and Go dependencies for the identified packages, investigate affected developer machines or CI/CD runners, rotate exposed credentials, review infrastructure activity, isolate compromised systems, and reimage affected hosts where necessary.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1195 Supply Chain Compromise -
Initial access T1195.001 Supply Chain Compromise Compromise Software Dependencies and Development Tools
Initial access T1195.002 Supply Chain Compromise Compromise Software Supply Chain
Persistence T1543.003 Create or Modify System Process Windows Service
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1573.001 Encrypted Channel Symmetric Cryptography
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Discovery E1082 System Information Discovery
Exfiltration E1020 Automated Exfiltration
Execution E1204 User Execution
Cryptography Micro-objective C0031 Decrypt Data
Defense Evasion B0029 Polymorphic Code
Anti-Static Analysis E1027 Obfuscated Files or Information
Discovery E1083 File and Directory Discovery

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu