Last seven days
- First activity
- Sep 22, 2026
- Last activity
- Sep 22, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 0 hostnames
RustyStealer is a Windows information-stealing malware family written in Rust and used to harvest credentials and other sensitive data from compromised systems.
Profile source: Mallory opens in a new tabRustyStealer
RustyStealer is a Windows information-stealing malware family written in Rust and used to harvest credentials and other sensitive data from compromised systems. It has been observed as both a standalone stealer and a launcher carrying an encrypted payload, and open reporting indicates it can also deliver additional malware. Documented intrusion chains show RustyStealer preceding hands-on-keyboard activity and later-stage ransomware deployment, including cases involving Ymir, where stolen high-privilege credentials enabled unauthorized access and lateral movement through remote administration mechanisms such as WinRM and PowerShell. It has also appeared as a payload in commodity botnet and pay-per-install ecosystems, including Amadey-driven distribution, alongside other stealers and remote access tools.
Operational reporting links RustyStealer to multiple threat contexts. It has been associated with financially motivated malware delivery operations and has also been reported as a tool used by the Iranian state-linked group MuddyWater. In Chinese-language intrusion activity attributed to the SilverFox cluster, RustyStealer has been used with social-engineering lures and persistence under legitimate-sounding executable names. Across these contexts, the malware is consistently characterized as a credential-harvesting infostealer that supports follow-on compromise.
Observed behavior includes collection of credentials and system information, command execution or remote control functionality in some incidents, and use as an access-enabling component for broader post-compromise operations. In ransomware-linked cases, RustyStealer infections were detected before encryption events and were assessed to have facilitated compromise of privileged accounts useful for lateral movement. Technical reporting also notes Rust-compiled launcher variants with AES-encrypted embedded payloads and obfuscation or packing characteristics consistent with evasive delivery tooling.
C2 tracking
Derp observations, rolling seven-day window
Samples
46fa26be6717553ade163809f26eb6f21357b64ebab3e92f53228fd38fe17b15 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e bdeeb6376f243f3a0081013593fdff3c2db1b5c4b6885fd761bd3906c18673ba dbc0d7546b385d189e70be289d0b101516a790d5a1c7380bbe35193d4fe28aee f51bd6b15fa0908f2996bbecdaaf7571a578a8d22df7a99c34b420b630fb8ac3 Reported operators
Sample 4: RustyStealer ... This is a Rust-compiled launcher carrying a 5.5 MB AES-encrypted payload.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.