Skip to content

KrustyLoader

KrustyLoader is a Rust-based initial-stage malware loader used to retrieve and launch second-stage payloads, most commonly the Sliver backdoor/C2 implant.

Profile source: Mallory opens in a new tab

KrustyLoader

Family profile

KrustyLoader is a Rust-based initial-stage malware loader used to retrieve and launch second-stage payloads, most commonly the Sliver backdoor/C2 implant. It was first documented in January 2024 in compromises of Ivanti Connect Secure systems exploiting CVE-2024-21887 and CVE-2023-46805, and has since been observed in additional exploitation chains involving Ivanti Endpoint Manager Mobile (EPMM), Ivanti Sentry, SAP NetWeaver, and Microsoft SharePoint/ToolShell intrusions. Reported delivery mechanisms include abuse of web shells and JSP loaders, direct retrieval from Amazon S3 infrastructure, and downloads via built-in utilities such as wget, curl, and fetch. On compromised Ivanti EPMM systems, KrustyLoader was reported to retrieve an AES-128-CFB encrypted Sliver payload, decrypt it using a hardcoded key and IV, and inject it into memory as shellcode. One report described an embedded staging URL that was hex-encoded, XOR-encrypted with key 0x49, and then AES-128-CFB encrypted; a decrypted example URL was http://abbeglasses.s3.amazonaws[.]com/dSn9tM. Public S3 infrastructure associated with payload delivery included openrbf.s3.amazonaws.com, tnegadge.s3.amazonaws.com, fconnect.s3.amazonaws.com, trkbucket.s3.amazonaws.com, the-mentor.s3.amazonaws.com, and tkshopqd.s3.amazonaws.com. KrustyLoader has been consistently associated with the China-nexus threat actor UNC5221, also tracked as UTA0178 and in some reporting as QuietCrabs, and has appeared in broader Chinese espionage activity alongside malware such as Zingdoor and ShadowPad. It has been observed targeting internet-exposed edge and enterprise systems across sectors including government, telecom, healthcare, finance, logistics, manufacturing, and universities. Although some vendors described it as Linux malware, reporting also documented Windows samples in incidents attributed to QuietCrabs. High-confidence related infrastructure and observables mentioned in the content include AWS S3-hosted payloads, attacker IPs 27.25.148[.]183, 64.52.80[.]21:4444, 103.244.88[.]125:8080, and connectivity to 146.70.87.67:45020.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 10, 2026
Last activity
Aug 10, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Amazon.com, Inc.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
UNC5221

On July 25, KrustyLoader was dropped by the attackers. KrustyLoader was first documented in January 2024. It is an initial-stage malware, written in Rust, which has the primary purpose of delivering a second-stage payload.

Exploited software

Vulnerabilities linked to KrustyLoader

5 CVEs

MITRE ATT&CK

KrustyLoader in ATT&CK

9 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.