logo

RustDuck: An In-Depth Analysis of a Two-Stage Botnet

ID: d590e6ea-59fa-53b3-ae7b-6a0f0771f988

STIX ID: report--d590e6ea-59fa-53b3-ae7b-6a0f0771f988

Feed Name: QiAnXin XLab

Threat Score
75/100

Date Published: 2026-06-30

Date Updated: 2026-07-02

Author: Wang Hao

...
...

RustDuck is a recently detected loader+core (two-stage) malware family focused on large-scale DDoS operations that is transitioning from C to Rust. The report documents four loader variants, a Rust-based core with advanced key derivation (HKDF-SHA256, Curve25519), strong transport encryption (ChaCha20, AES-GCM), anti-debugging/sandbox checks, and a command-and-control protocol. Propagation leverages weak SSH/Telnet credentials and multiple IoT/web RCEs (including several CVEs) across routers, cameras, Android devices, and servers; the report also provides sample SHA1s, C2 domains, and observed implant IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.