Skip to content

KrustyLoader

KrustyLoader is a Rust-based initial-stage malware family used to retrieve and launch follow-on payloads, most notably the Sliver command-and-control implant.

Profile source: Mallory opens in a new tab

KrustyLoader

Family profile

KrustyLoader is a Rust-based initial-stage malware family used to retrieve and launch follow-on payloads, most notably the Sliver command-and-control implant. It has been observed in both Linux and Windows variants. On Linux, samples associated with exploitation of edge and enterprise applications perform execution-environment checks, decrypt an embedded staging URL, download an encrypted second-stage payload, write it to a temporary location, make it executable, execute it, and delete themselves from disk. On Windows, observed samples retrieve an encrypted Sliver payload from cloud storage, decrypt it in memory, inject it into a legitimate process, and remove the loader from disk to reduce forensic visibility.

KrustyLoader is closely associated with China-nexus intrusion activity, especially clusters tracked as UNC5221, UTA0178, and QuietCrabs. It has been used after exploitation of internet-facing systems including Ivanti Connect Secure, Ivanti Endpoint Manager Mobile, SAP NetWeaver, and Microsoft SharePoint, typically following deployment of web shells or other post-compromise tooling. Reporting also places it alongside broader Chinese espionage tradecraft involving long-term access, credential theft, reconnaissance, and lateral movement through the delivered Sliver implant and related utilities.

The malware uses layered obfuscation and encrypted configuration material, including staged URL decryption and encrypted payload retrieval. Documented Linux samples include anti-analysis and execution-guard logic, such as self-path checks, parent-process validation, and anti-debugging behavior. Across observed campaigns, KrustyLoader’s primary role is as a downloader or loader that enables covert post-exploitation access rather than acting as the final persistence or espionage platform itself. Victimology has included government, telecommunications, healthcare, finance, universities, and other organizations operating exposed edge or enterprise infrastructure.

Capabilities

  • Defense Evasion
  • Initial Access
  • Post Exploitation
  • Process Injection

Reported operators

Threat actors

1 named in public reporting
UNC5221

KrustyLoader is a downloader that retrieves an encrypted Sliver payload from a second S3 location, injects it into Windows Explorer, and erases itself from disk, leaving the cyber threat actors (CTAs) with immediate covert access to victims’ systems.

Exploited software

Vulnerabilities linked to KrustyLoader

10 CVEs

MITRE ATT&CK

KrustyLoader in ATT&CK

17 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.