logo

Operation RusticWeb: Rust-Based Malware Targets Indian Government Entities

ID: 10089ab8-aee4-51d7-8ac7-bdea004933f2

STIX ID: report--10089ab8-aee4-51d7-8ac7-bdea004933f2

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2023-12-22

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Operation RusticWeb is a multi-stage phishing campaign observed since October 2023 targeting Indian government and defense organizations; it delivers Rust-based payloads and encrypted PowerShell scripts to enumerate systems, collect files and system information, and exfiltrate data to a public file-sharing service (oshi.at/OshiUpload). Analysts note overlaps with Pakistan-linked APT clusters such as Transparent Tribe and SideCopy, and a related chain uses a Rust executable masquerading as "Cisco AnyConnect Web Helper"; the activity demonstrates targeted espionage-focused capabilities rather than broad destructive operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.