logo

New Rust Botnet "RustoBot" is Routed via Routers

ID: e656ec5f-9d3c-5a35-8abe-8b6b53f9db75

STIX ID: report--e656ec5f-9d3c-5a35-8abe-8b6b53f9db75

Feed Name: Fortinet Blog

Threat Score
75/100

Date Published: 2025-04-21

Date Updated: 2026-04-27

...
...

FortiGuard Labs discovered and analyzed “RustoBot,” a Rust-written botnet that exploits command-injection flaws in TOTOLINK and DrayTek devices (including CVE-2024-12987 and multiple TOTOLINK CVEs) to gain remote control and launch DDoS attacks; the report covers downloader behavior, architecture variants, C2 infrastructure, observed incidents across Japan, Taiwan, Vietnam, and Mexico, IOCs (URLs, hosts, file hashes), and Fortinet protections and recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.