New Rust Botnet "RustoBot" is Routed via Routers
ID: e656ec5f-9d3c-5a35-8abe-8b6b53f9db75
STIX ID: report--e656ec5f-9d3c-5a35-8abe-8b6b53f9db75
Feed Name: Fortinet Blog
Threat Score
FortiGuard Labs discovered and analyzed “RustoBot,” a Rust-written botnet that exploits command-injection flaws in TOTOLINK and DrayTek devices (including CVE-2024-12987 and multiple TOTOLINK CVEs) to gain remote control and launch DDoS attacks; the report covers downloader behavior, architecture variants, C2 infrastructure, observed incidents across Japan, Taiwan, Vietnam, and Mexico, IOCs (URLs, hosts, file hashes), and Fortinet protections and recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
