Skip to content

Rustonotto

Rustonotto is a Rust-compiled Windows backdoor associated with the North Korean threat actor APT37, also known as ScarCruft or Reaper.

Profile source: Mallory opens in a new tab

Rustonotto

Family profile

Rustonotto is a Rust-compiled Windows backdoor associated with the North Korean threat actor APT37, also known as ScarCruft or Reaper. It has been reported in operations pairing a Python loader with a Rust-based HTTP backdoor, indicating a modular intrusion chain in which an initial component deploys or launches the backdoor on victim systems.

Rustonotto is characterized as an HTTP backdoor that exchanges commands and responses using Base64 encoding. This supports post-compromise remote tasking over web protocols while blending command traffic into normal network activity. As a backdoor, it enables continued attacker access to infected hosts and is consistent with espionage-oriented tradecraft historically associated with APT37.

Observed reporting links Rustonotto to Windows-focused campaigns and to spearphishing-driven intrusion scenarios reflected in related detection coverage for malicious Office document execution and uncommon child processes spawned by Office applications. The malware appears in the context of APT37 activity targeting strategically relevant victims, particularly in and around South Korea, although precise victimology for Rustonotto specifically is not fully established from the available information.

High-confidence attribution ties Rustonotto to APT37, a long-running North Korean espionage actor known for targeting government, diplomatic, policy, activist, and other intelligence-relevant entities. Rustonotto fits that broader operational pattern as a stealthy backdoor intended to maintain access and support follow-on actions on compromised Windows endpoints.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation

Reported operators

Threat actors

1 named in public reporting
APT37

APT37 Targets Windows with Rust Backdoor and Python Loader Rustonotto

Exploited software

Vulnerabilities linked to Rustonotto

1 CVEs

MITRE ATT&CK

Rustonotto in ATT&CK

3 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.