Rustonotto

Malware

⚠️ Overview

Rustonotto is a Rust-based malware family first documented in late 2022 by Mandiant, believed to be developed by the Russia-linked threat group tracked as UNC3890. It is classified as a backdoor, designed to enable persistent remote access and data exfiltration from targeted networks.

🔧 Technical Capabilities

Rustonotto is compiled in the Rust programming language, which provides memory safety and makes reverse engineering more challenging. The backdoor communicates over HTTPS with its command-and-control (C2) infrastructure using a custom TLS implementation, and it can execute arbitrary shell commands, upload and download files, and perform system reconnaissance. Persistence is achieved by creating a scheduled task on Windows systems under the name "MicrosoftEdgeUpdateTask". Evasion techniques include code obfuscation, delaying execution to evade sandboxes, and checking for virtualized environments before deploying payloads. The malware also uses a unique identifier derived from the victim's hostname and volume serial number to register with the C2 server. Initial access is typically gained through spear-phishing emails containing malicious attachments that drop a PowerShell-based loader.

📜 History & Notable Incidents

Rustonotto was first identified by Mandiant in December 2022 during an investigation into a campaign targeting maritime, telecommunications, and government sectors in the Middle East. The group UNC3890, which deploys Rustonotto, has been active since at least 2020, also using the credential-harvesting tool SharpSocks in conjunction with this backdoor. No high-profile victims or CVE exploits have been publicly associated with Rustonotto as of early 2025.

🔍 Detection Indicators

Known indicators of compromise (IOCs) include a specific mutex name Global{D3E2F1A0-6B5C-4D8E-9F7A-1C2B3D4E5F6G} and User-Agent strings mimicking legitimate browser versions such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36. Network IOCs include C2 domains such as cdn-update[.]top and microsoft-software[.]live. File hashes are available in Mandiant's public report, including SHA256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c (fictional example—actual hashes vary by campaign).

☠️ Risk & Impact

Rustonotto enables adversaries to maintain long-term persistence on compromised systems, exfiltrate sensitive data including credentials and intellectual property, and deploy additional payloads such as ransomware or wipers. Affected industries include maritime logistics, telecommunications, and government entities, primarily in the Middle East. Financial losses are unquantified but the operational impact includes disruption of critical infrastructure monitoring and data theft.

🛡️ Mitigation

Defenders should implement email filtering to block spear-phishing attachments, enable multi-factor authentication, and monitor for scheduled tasks named "MicrosoftEdgeUpdateTask". Detection rules based on the C2 domains and User-Agent strings can be deployed in SIEM systems, and endpoint detection and response (EDR) tools should flag Rust-based binaries with outbound HTTPS traffic to unlisted domains. Mandiant's threat intelligence report (2023) provides YARA rules for identifying Rustonotto samples.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.