Palo Alto Networks Unit 42 reported that malware written in Go had grown steadily in the wild, based on analysis of roughly 10,700 unique samples collected from VirusTotal and internal repositories. After filtering out about 2,000 false positives through YARA matching and manual clustering, researchers found that 75% of the remaining samples could be assigned to known malware families, identifying 53 distinct families overall.
The study found that 92% of identified Go malware targeted Windows, with Linux and macOS representing much smaller portions of the dataset. The most prevalent families included Veil, GoBot2, and HERCULES, while the most common category was penetration-testing-related tooling, followed by RATs, backdoors, coinminers, and information stealers, indicating that Go was becoming an increasingly attractive language for cross-platform malicious tooling.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The research observed a significant increase in identified Go-based malware samples during the January-to-March period across 2017 through 2019, with counts rising by nearly 20 times overall. This trend was cited as evidence that Go malware was steadily gaining popularity.
Palo Alto Networks Unit 42 published research analyzing roughly 10,700 unique Go-based malware samples after filtering and validation. The study identified 53 malware families, found Windows was the dominant target platform, and reported that Go malware remained limited but was steadily increasing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.