Operation RusticWeb: Rust-Based Malware Targets Indian Government Entities
ID: 10089ab8-aee4-51d7-8ac7-bdea004933f2
STIX ID: report--10089ab8-aee4-51d7-8ac7-bdea004933f2
Feed Name: The Hacker News
Operation RusticWeb is a multi-stage phishing campaign observed since October 2023 targeting Indian government and defense organizations; it delivers Rust-based payloads and encrypted PowerShell scripts to enumerate systems, collect files and system information, and exfiltrate data to a public file-sharing service (oshi.at/OshiUpload). Analysts note overlaps with Pakistan-linked APT clusters such as Transparent Tribe and SideCopy, and a related chain uses a Rust executable masquerading as "Cisco AnyConnect Web Helper"; the activity demonstrates targeted espionage-focused capabilities rather than broad destructive operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
