#GopherGrabber

Malware/Tool

2025-04-22 • Analysis of TraderTraitor’s GopherGrabber Malware observed by Willo Campaign

GopherGrabber is a cross-platform Go malware family used in the TraderTraitor-linked Willo campaign. It combines backdoor and information-stealing functions and communicates with a command-and-control server over HTTP or HTTPS. The malware appeared as directly executable Go-project source and was delivered through malicious npm packages in June 2024 and later through an installer disguised as the Versus X service. This distribution model targeted software and cryptocurrency ecosystems through both package supply-chain compromise and deceptive installers.

Tagged Reports

« Back