Last seven days
- First activity
- Aug 10, 2026
- Last activity
- Aug 10, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
KrustyLoader is a Rust-based initial-stage malware loader used to retrieve and launch second-stage payloads, most commonly the Sliver backdoor/C2 implant.
Profile source: Mallory opens in a new tabKrustyLoader
KrustyLoader is a Rust-based initial-stage malware loader used to retrieve and launch second-stage payloads, most commonly the Sliver backdoor/C2 implant. It was first documented in January 2024 in compromises of Ivanti Connect Secure systems exploiting CVE-2024-21887 and CVE-2023-46805, and has since been observed in additional exploitation chains involving Ivanti Endpoint Manager Mobile (EPMM), Ivanti Sentry, SAP NetWeaver, and Microsoft SharePoint/ToolShell intrusions. Reported delivery mechanisms include abuse of web shells and JSP loaders, direct retrieval from Amazon S3 infrastructure, and downloads via built-in utilities such as wget, curl, and fetch. On compromised Ivanti EPMM systems, KrustyLoader was reported to retrieve an AES-128-CFB encrypted Sliver payload, decrypt it using a hardcoded key and IV, and inject it into memory as shellcode. One report described an embedded staging URL that was hex-encoded, XOR-encrypted with key 0x49, and then AES-128-CFB encrypted; a decrypted example URL was http://abbeglasses.s3.amazonaws[.]com/dSn9tM. Public S3 infrastructure associated with payload delivery included openrbf.s3.amazonaws.com, tnegadge.s3.amazonaws.com, fconnect.s3.amazonaws.com, trkbucket.s3.amazonaws.com, the-mentor.s3.amazonaws.com, and tkshopqd.s3.amazonaws.com. KrustyLoader has been consistently associated with the China-nexus threat actor UNC5221, also tracked as UTA0178 and in some reporting as QuietCrabs, and has appeared in broader Chinese espionage activity alongside malware such as Zingdoor and ShadowPad. It has been observed targeting internet-exposed edge and enterprise systems across sectors including government, telecom, healthcare, finance, logistics, manufacturing, and universities. Although some vendors described it as Linux malware, reporting also documented Windows samples in incidents attributed to QuietCrabs. High-confidence related infrastructure and observables mentioned in the content include AWS S3-hosted payloads, attacker IPs 27.25.148[.]183, 64.52.80[.]21:4444, 103.244.88[.]125:8080, and connectivity to 146.70.87.67:45020.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
On July 25, KrustyLoader was dropped by the attackers. KrustyLoader was first documented in January 2024. It is an initial-stage malware, written in Rust, which has the primary purpose of delivering a second-stage payload.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.