Skip to content

Rustonotto

Rustonotto is a malware family associated in the provided content with APT37 and the analytic story "APT37 Rustonotto and FadeStealer." The content explicitly describes it as a "Rust-compiled HTTP/Backdoor" that uses Base64-encoded commands and responses.

Profile source: Mallory opens in a new tab

Rustonotto

Family profile

Rustonotto is a malware family associated in the provided content with APT37 and the analytic story "APT37 Rustonotto and FadeStealer." The content explicitly describes it as a "Rust-compiled HTTP/Backdoor" that uses Base64-encoded commands and responses. High-confidence references place it in Windows-focused detection and hunting contexts tied to spearphishing attachment activity, including Microsoft Office–delivered execution chains and detections such as "Windows Office Product Dropped Cab or Inf File" associated with CVE-2021-40444, as well as "Windows Office Product Spawned Uncommon Process." Additional related detections and stories in the content connect Rustonotto to suspicious download and execution behaviors on Windows, including curl downloads to suspicious paths, suspicious LNK creation, startup-folder persistence-related file drops, malicious URL shortcut creation, msiexec HTTP/HTTPS communication, process injection into commonly abused processes, scheduled task abuse, indicator removal via rmdir, and high file deletion frequency. The content does not provide specific IOCs such as hashes, domains, or filenames for Rustonotto itself beyond the malware name and the characterization as a Rust-compiled HTTP backdoor using Base64 command-and-response handling.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 8, 2026
Last activity
Aug 8, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • KR1

Leading providers

  • Korea Telecom1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
APT37

“Rustonotto: Rust-compiled HTTP/Backdoor (Base64 commands and responses)”

Exploited software

Vulnerabilities linked to Rustonotto

1 CVEs

MITRE ATT&CK

Rustonotto in ATT&CK

3 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.