StealthWorker is a Golang-based malware family and botnet associated with large-scale internet scanning and credential attacks against internet-exposed systems. It was initially observed compromising web-facing services and e-commerce environments, including platforms such as Magento, phpMyAdmin, cPanel, WooCommerce, WordPress, OpenCart, Bitrix24, PostgreSQL, and network-attached storage devices from vendors including QNAP and Synology. Over time it evolved from earlier Windows-focused activity into Linux-capable malware, broadening its utility against servers and NAS appliances.
A defining characteristic of StealthWorker is automated brute-force activity against administrative and HTTP-authenticated services using generated passwords and previously compromised credentials. Successful compromises can be used to enroll victims into the botnet and to launch further attacks against additional Linux-based devices. The malware has been reported to upload harvested valid credentials to command-and-control infrastructure and to create scheduled tasks on both Windows and Linux for persistence.
StealthWorker has also been linked to second-stage payload delivery after initial compromise. Reported follow-on activity includes deployment of ransomware against compromised NAS devices, and earlier campaigns involved payment-card skimming and theft of personal information from compromised e-commerce sites. Its operational profile therefore spans credential abuse, botnet propagation, persistence, and post-compromise payload delivery.
The malware has been notably associated with attacks on internet-exposed NAS systems, which are attractive targets because they often contain valuable backup data and are frequently administered with weak or default credentials. In Synology-related incidents, compromised devices were subsequently used to attack other Linux systems, illustrating StealthWorker’s role as both an intrusion tool and a propagation platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
93 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool listed as detectable via SHA-256 hash in a compilation of attacker infrastructure and malware-related indicators.
A Golang-based brute-force malware/botnet that scans for Internet-exposed devices and Linux systems with weak or default credentials, installs a malicious payload after successful login, creates scheduled tasks on Windows and Linux for persistence, and can deploy second-stage payloads including ransomware.
Mentioned only as part of a list of malware tied to abandoned C2 infrastructure discovered during analysis.
Botnet/brute-force malware that evolved from Windows to Linux and targets NAS devices and web applications by brute-forcing credentials, then uploads valid credentials to its C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.