Last seven days
- First activity
- Aug 8, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Rustonotto is a malware family associated in the provided content with APT37 and the analytic story "APT37 Rustonotto and FadeStealer." The content explicitly describes it as a "Rust-compiled HTTP/Backdoor" that uses Base64-encoded commands and responses.
Profile source: Mallory opens in a new tabRustonotto
Rustonotto is a malware family associated in the provided content with APT37 and the analytic story "APT37 Rustonotto and FadeStealer." The content explicitly describes it as a "Rust-compiled HTTP/Backdoor" that uses Base64-encoded commands and responses. High-confidence references place it in Windows-focused detection and hunting contexts tied to spearphishing attachment activity, including Microsoft Office–delivered execution chains and detections such as "Windows Office Product Dropped Cab or Inf File" associated with CVE-2021-40444, as well as "Windows Office Product Spawned Uncommon Process." Additional related detections and stories in the content connect Rustonotto to suspicious download and execution behaviors on Windows, including curl downloads to suspicious paths, suspicious LNK creation, startup-folder persistence-related file drops, malicious URL shortcut creation, msiexec HTTP/HTTPS communication, process injection into commonly abused processes, scheduled task abuse, indicator removal via rmdir, and high file deletion frequency. The content does not provide specific IOCs such as hashes, domains, or filenames for Rustonotto itself beyond the malware name and the characterization as a Rust-compiled HTTP backdoor using Base64 command-and-response handling.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
“Rustonotto: Rust-compiled HTTP/Backdoor (Base64 commands and responses)”
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.