...after the discovery of NimRod/Nimza and RustyBuer which are both being leveraged by actors associated with the TrickBot crew.
RustyBuer
RustyBuer is a Rust-based rewrite of the Buer malware family designed to preserve compatibility with existing Buer command-and-control infrastructure while improving evasion against detections focused on earlier C-based builds.
Profile source: Mallory opens in a new tabRustyBuer
Family profile
RustyBuer is a Rust-based rewrite of the Buer malware family designed to preserve compatibility with existing Buer command-and-control infrastructure while improving evasion against detections focused on earlier C-based builds. It functions primarily as a first-stage malware-as-a-service loader or downloader used to establish an initial foothold on Windows systems and retrieve additional payloads. Observed follow-on payloads have included Cobalt Strike Beacon, and Buer operators have been assessed in some cases to support access-as-a-service activity by selling or transferring compromised access to other threat actors. RustyBuer has also been discussed in reporting on tooling associated with actors linked to the TrickBot ecosystem.
Observed delivery has relied on phishing campaigns themed as shipping notices, with victims lured to malicious Microsoft Office documents. Infection required user interaction to enable macro execution, after which the document dropped and launched the Rust-based payload. Campaigns used a Windows Shell DLL application-bypass technique involving trusted system components to reduce endpoint detection opportunities, and persistence was established through startup shortcut creation.
RustyBuer includes anti-analysis and regional filtering logic. Documented behavior includes virtual-machine checks and locale checks intended to avoid execution in certain CIS environments. During beaconing, the malware collects host profiling data such as operating system version, architecture, privilege level, computer and user context, processor information, disk usage, and Active Directory domain details, then transmits this information to its controllers over HTTP(S). Server responses can instruct the malware to download and execute additional payloads.
Campaigns distributing RustyBuer affected organizations across a wide range of industry verticals, consistent with its role as broadly distributed initial-access malware rather than sector-specific tooling.
Capabilities
- Defense Evasion
- Initial Access
- Persistence
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK