logo

Operation RusticWeb targets Indian Govt: From Rust-based malware to Web-service exfiltration

ID: b7626bab-c4aa-5204-8e90-1b6c49f4a117

STIX ID: report--b7626bab-c4aa-5204-8e90-1b6c49f4a117

Feed Name: Seqrite Blog

Threat Score
78/100

Date Published: 2023-12-21

Date Updated: 2026-04-30

Author: Sathwik Ram Prakki

...
...

SEQRITE Labs describes Operation RusticWeb, a spear-phishing campaign active since October 2023 targeting Indian government and defence-sector personnel using fake government-themed lures. Attackers deploy Rust-compiled binaries and encrypted PowerShell/maldocs to enumerate files and exfiltrate sensitive documents to public file-sharing services (OshiUpload) and cloud backends, using fake domains (e.g., awesscholarship.in, parichay.epar.in) for payload hosting; the report includes detailed infection chains, IOCs (MD5s, domains, URLs, PDBs, host paths), MITRE ATT&CK mappings, and detection identifiers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.