RustDuck: An In-Depth Analysis of a Two-Stage Botnet
ID: d590e6ea-59fa-53b3-ae7b-6a0f0771f988
STIX ID: report--d590e6ea-59fa-53b3-ae7b-6a0f0771f988
Feed Name: QiAnXin XLab
RustDuck is a recently detected loader+core (two-stage) malware family focused on large-scale DDoS operations that is transitioning from C to Rust. The report documents four loader variants, a Rust-based core with advanced key derivation (HKDF-SHA256, Curve25519), strong transport encryption (ChaCha20, AES-GCM), anti-debugging/sandbox checks, and a command-and-control protocol. Propagation leverages weak SSH/Telnet credentials and multiple IoT/web RCEs (including several CVEs) across routers, cameras, Android devices, and servers; the report also provides sample SHA1s, C2 domains, and observed implant IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
