Skip to content

RustyStealer

RustyStealer is a Windows information-stealing malware family written in Rust and used to harvest credentials and other sensitive data from compromised systems.

Profile source: Mallory opens in a new tab

RustyStealer

Family profile

RustyStealer is a Windows information-stealing malware family written in Rust and used to harvest credentials and other sensitive data from compromised systems. It has been observed as both a standalone stealer and a launcher carrying an encrypted payload, and open reporting indicates it can also deliver additional malware. Documented intrusion chains show RustyStealer preceding hands-on-keyboard activity and later-stage ransomware deployment, including cases involving Ymir, where stolen high-privilege credentials enabled unauthorized access and lateral movement through remote administration mechanisms such as WinRM and PowerShell. It has also appeared as a payload in commodity botnet and pay-per-install ecosystems, including Amadey-driven distribution, alongside other stealers and remote access tools.

Operational reporting links RustyStealer to multiple threat contexts. It has been associated with financially motivated malware delivery operations and has also been reported as a tool used by the Iranian state-linked group MuddyWater. In Chinese-language intrusion activity attributed to the SilverFox cluster, RustyStealer has been used with social-engineering lures and persistence under legitimate-sounding executable names. Across these contexts, the malware is consistently characterized as a credential-harvesting infostealer that supports follow-on compromise.

Observed behavior includes collection of credentials and system information, command execution or remote control functionality in some incidents, and use as an access-enabling component for broader post-compromise operations. In ransomware-linked cases, RustyStealer infections were detected before encryption events and were assessed to have facilitated compromise of privileged accounts useful for lateral movement. Technical reporting also notes Rust-compiled launcher variants with AES-encrypted embedded payloads and obfuscation or packing characteristics consistent with evasive delivery tooling.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 8, 2026
Last activity
Sep 8, 2026
Feed role
C2 / Distribution
Host form
1 IP / 0 hostnames

Leading locations

  • NL1

Leading providers

  • Omegatech LTD1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Silver Fox

Sample 4: RustyStealer ... This is a Rust-compiled launcher carrying a 5.5 MB AES-encrypted payload.

MITRE ATT&CK

RustyStealer in ATT&CK

21 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.