Last seven days
- First activity
- Sep 8, 2026
- Last activity
- Sep 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 0 hostnames
RustyStealer is a Windows information-stealing malware family written in Rust and used to harvest credentials and other sensitive data from compromised systems.
Profile source: Mallory opens in a new tabRustyStealer
RustyStealer is a Windows information-stealing malware family written in Rust and used to harvest credentials and other sensitive data from compromised systems. It has been observed as both a standalone stealer and a launcher carrying an encrypted payload, and open reporting indicates it can also deliver additional malware. Documented intrusion chains show RustyStealer preceding hands-on-keyboard activity and later-stage ransomware deployment, including cases involving Ymir, where stolen high-privilege credentials enabled unauthorized access and lateral movement through remote administration mechanisms such as WinRM and PowerShell. It has also appeared as a payload in commodity botnet and pay-per-install ecosystems, including Amadey-driven distribution, alongside other stealers and remote access tools.
Operational reporting links RustyStealer to multiple threat contexts. It has been associated with financially motivated malware delivery operations and has also been reported as a tool used by the Iranian state-linked group MuddyWater. In Chinese-language intrusion activity attributed to the SilverFox cluster, RustyStealer has been used with social-engineering lures and persistence under legitimate-sounding executable names. Across these contexts, the malware is consistently characterized as a credential-harvesting infostealer that supports follow-on compromise.
Observed behavior includes collection of credentials and system information, command execution or remote control functionality in some incidents, and use as an access-enabling component for broader post-compromise operations. In ransomware-linked cases, RustyStealer infections were detected before encryption events and were assessed to have facilitated compromise of privileged accounts useful for lateral movement. Technical reporting also notes Rust-compiled launcher variants with AES-encrypted embedded payloads and obfuscation or packing characteristics consistent with evasive delivery tooling.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 9f0a4fce6d13c892326cf6788258b035118901d2551e43cc214083acc7ff2a24 e72b03d7ce71ec92460622726d6bc55228eb8a62d39e82d8749f45fe497ba35c Reported operators
Sample 4: RustyStealer ... This is a Rust-compiled launcher carrying a 5.5 MB AES-encrypted payload.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.