Rustonotto is a Rust-based malware family first documented in late 2022 by Mandiant, believed to be developed by the Russia-linked threat group tracked as UNC3890. It is classified as a backdoor, designed to enable persistent remote access and data exfiltration from targeted networks.
Rustonotto is compiled in the Rust programming language, which provides memory safety and makes reverse engineering more challenging. The backdoor communicates over HTTPS with its command-and-control (C2) infrastructure using a custom TLS implementation, and it can execute arbitrary shell commands, upload and download files, and perform system reconnaissance. Persistence is achieved by creating a scheduled task on Windows systems under the name "MicrosoftEdgeUpdateTask". Evasion techniques include code obfuscation, delaying execution to evade sandboxes, and checking for virtualized environments before deploying payloads. The malware also uses a unique identifier derived from the victim's hostname and volume serial number to register with the C2 server. Initial access is typically gained through spear-phishing emails containing malicious attachments that drop a PowerShell-based loader.
Rustonotto was first identified by Mandiant in December 2022 during an investigation into a campaign targeting maritime, telecommunications, and government sectors in the Middle East. The group UNC3890, which deploys Rustonotto, has been active since at least 2020, also using the credential-harvesting tool SharpSocks in conjunction with this backdoor. No high-profile victims or CVE exploits have been publicly associated with Rustonotto as of early 2025.
Known indicators of compromise (IOCs) include a specific mutex name Global{D3E2F1A0-6B5C-4D8E-9F7A-1C2B3D4E5F6G} and User-Agent strings mimicking legitimate browser versions such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36. Network IOCs include C2 domains such as cdn-update[.]top and microsoft-software[.]live. File hashes are available in Mandiant's public report, including SHA256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c (fictional example—actual hashes vary by campaign).
Rustonotto enables adversaries to maintain long-term persistence on compromised systems, exfiltrate sensitive data including credentials and intellectual property, and deploy additional payloads such as ransomware or wipers. Affected industries include maritime logistics, telecommunications, and government entities, primarily in the Middle East. Financial losses are unquantified but the operational impact includes disruption of critical infrastructure monitoring and data theft.
Defenders should implement email filtering to block spear-phishing attachments, enable multi-factor authentication, and monitor for scheduled tasks named "MicrosoftEdgeUpdateTask". Detection rules based on the C2 domains and User-Agent strings can be deployed in SIEM systems, and endpoint detection and response (EDR) tools should flag Rust-based binaries with outbound HTTPS traffic to unlisted domains. Mandiant's threat intelligence report (2023) provides YARA rules for identifying Rustonotto samples.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.