
DEF CON 33 - Go Malware Meets IoT - Challenges, Blind Spots, and Botnets - Asher Davila
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 47:35
The presentation discusses the growing trend of Golang-based malware, analyzing why malware authors are increasingly using Go and examining the challenges in analyzing such malware 0:52. Key characteristics of Go that make it attractive to malware writers include cross-platform support, self-contained statically linked binaries, and increased difficulty for static analysis compared to C/C++ 1:33.
The speakers present several examples of Go-based malware families including GoBruteforcer, SeacryGo, CodeTier, and Pumabot, demonstrating how this malware targets various platforms and systems 3:24. They highlight the analysis challenges posed by Go malware, such as large file sizes, high function counts, tooling limitations, and unique string handling mechanisms 5:29.
The presentation showcases various tools and techniques for analyzing Go binaries, including Ghidra with Go-specific plugins, radare2, and AI-assisted analysis tools like R2AI and Ghidra MCP 7:08. They demonstrate practical analysis of IoT malware samples like BotanaGo and Pumabot, showing how to extract configuration data, identify command and control infrastructure, and reconstruct attack payloads 23:14.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
My name is Asher Davila. I'm a principal security researcher for Palaton Networks. Uh mainly working on IoT and OT vulnerabilities and malware research. I've presented at multiple conference including like Devcon, RSA, S4 and you can find me everywhere as Ashure Davila. Hello everyone. Uh my name is Chris. I am a senior principal security researcher working for Palto Networks. I uh focus on the detection engineering especially in C2 frameworks uh malware and I am part of the advanced threat prevention team. So everything about global strike anything like that. So I'm pretty much the owner of that. Uh previously I have presented at Blahad Asia briefings and the Blahad US Arsenal and some other um conference as well. So you have the link in here if you want to connect to it. All right. So uh…