Home Artists Posts Import Register

Content

In this stream we take a look at this RootTeam is a GO stealer that can be built via a Telegram channel. Originally we confused this with BanditStealer but it is separate ... also we try of this neat GO symbol recovery tool GO IDA parser!

Samples

e0cd16b3de1f8b6c91b3483e383199f691e935d3d4e1ed9e77f6f9aea929b68b

Notes

RootTeam - Taking a look at this free GO stealer 

Files

Live Stream VOD: RootTeam GoLang Stealer

This is "Live Stream VOD: RootTeam GoLang Stealer" by OALABS on Vimeo, the home for high quality videos and the people who love them.

Comments

m4n0w4r

Note from GoReSym: To import this information into IDA Pro you can run the script found in https://github.com/mandiant/GoReSym/blob/master/IDAPython/goresym_rename.py. It will read a json file produced by GoReSym and set symbols/labels in IDA.