Skip to content

RustyStealer

RustyStealer is a Rust-based Windows information stealer focused on harvesting credentials and other user data from compromised systems.

Profile source: Mallory opens in a new tab

RustyStealer

Family profile

RustyStealer is a Rust-based Windows information stealer focused on harvesting credentials and other user data from compromised systems. Reporting links it to credential theft, browser session theft, and cryptocurrency wallet theft, and in some intrusion chains it has been used as an access-enabling precursor to later-stage operations including ransomware deployment. It has also been described as capable of giving operators remote control over infected machines, allowing command execution and information gathering across victim environments.

RustyStealer has appeared in both commodity cybercrime distribution ecosystems and more targeted intrusion activity. It has been observed as a payload delivered by the Amadey botnet in pay-per-install style campaigns alongside other stealers, RATs, loaders, and abused remote management tools. In enterprise intrusions, RustyStealer infections have preceded lateral movement through compromised high-privilege accounts and remote administration mechanisms, contributing to broader post-compromise activity. Open-source reporting has also associated RustyStealer with MuddyWater, indicating use beyond purely commodity crimeware contexts.

Observed samples indicate a Rust-compiled launcher architecture with an encrypted payload, and some variants establish persistence by copying themselves under legitimate-sounding names in shared system locations. Across documented campaigns, the malware has been used against Windows environments and has featured in lure-driven operations targeting Chinese-speaking users as well as in broader financially motivated malware distribution. Its operational role is most consistently that of an infostealer that supports credential access, session theft, persistence, and follow-on compromise.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Persistence
  • Post Exploitation
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 6, 2026
Last activity
Aug 6, 2026
Feed role
C2 / Distribution
Host form
1 IP / 0 hostnames

Leading locations

  • LU1

Leading providers

  • Ghosty Networks LLC1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Silver Fox

Sample 4: RustyStealer ... This is a Rust-compiled launcher carrying a 5.5 MB AES-encrypted payload.

MITRE ATT&CK

RustyStealer in ATT&CK

21 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.