Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 0 hostnames
RustyStealer is a Rust-based Windows information stealer focused on harvesting credentials and other user data from compromised systems.
Profile source: Mallory opens in a new tabRustyStealer
RustyStealer is a Rust-based Windows information stealer focused on harvesting credentials and other user data from compromised systems. Reporting links it to credential theft, browser session theft, and cryptocurrency wallet theft, and in some intrusion chains it has been used as an access-enabling precursor to later-stage operations including ransomware deployment. It has also been described as capable of giving operators remote control over infected machines, allowing command execution and information gathering across victim environments.
RustyStealer has appeared in both commodity cybercrime distribution ecosystems and more targeted intrusion activity. It has been observed as a payload delivered by the Amadey botnet in pay-per-install style campaigns alongside other stealers, RATs, loaders, and abused remote management tools. In enterprise intrusions, RustyStealer infections have preceded lateral movement through compromised high-privilege accounts and remote administration mechanisms, contributing to broader post-compromise activity. Open-source reporting has also associated RustyStealer with MuddyWater, indicating use beyond purely commodity crimeware contexts.
Observed samples indicate a Rust-compiled launcher architecture with an encrypted payload, and some variants establish persistence by copying themselves under legitimate-sounding names in shared system locations. Across documented campaigns, the malware has been used against Windows environments and has featured in lure-driven operations targeting Chinese-speaking users as well as in broader financially motivated malware distribution. Its operational role is most consistently that of an infostealer that supports credential access, session theft, persistence, and follow-on compromise.
C2 tracking
Derp observations, rolling seven-day window
Samples
2e2e035ece4accdee838ecaacdc263fa526939597954d18d1320d73c8bf810c2 2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 Reported operators
Sample 4: RustyStealer ... This is a Rust-compiled launcher carrying a 5.5 MB AES-encrypted payload.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.