RustyRocket
Malware⚠️ Overview
RustyRocket is a Rust-based Remote Access Trojan (RAT) first documented by Fortinet’s FortiGuard Labs in August 2023, attributed to an advanced persistent threat (APT) group tracked as TA4563 with suspected ties to Chinese espionage operations. It primarily targets defense contractors, telecommunications firms, and government entities across Southeast Asia and Europe, falling under the categories of RAT and information stealer.
🔧 Technical Capabilities
RustyRocket propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2023-38831 (a WinRAR vulnerability) to drop the payload. Its C2 infrastructure uses encrypted HTTPS with custom binary protocols and leverages domain fronting via Cloudflare CDN to evade network detection. Persistence is achieved through a scheduled task named “RuntimeBroker” that launches a PowerShell script loading the malware as a reflective DLL. Evasion techniques include sandbox detection by checking for debugger artifacts, process hollowing against “svchost.exe,” and dynamic API resolution to avoid static signature matching. The malware collects system information, keystrokes, clipboard data, and files matching extensions like .docx, .pdf, and .xls, exfiltrating them via HTTP POST requests to a C2 server.
📜 History & Notable Incidents
First spotted in June 2023 during a campaign targeting Philippine government portals, RustyRocket gained prominence in November 2023 when it was used in a supply-chain attack against a European satellite communications provider, compromising internal VPN credentials. MITRE ATT&CK IDs associated include T1566.001 (Spearphishing Attachment), T1059.001 (PowerShell), and T1574.002 (DLL Side-Loading). No CVEs are directly attributed to the malware itself; it exploits CVE-2023-38831 for initial access.
🔍 Detection Indicators
Known SHA-256 hashes include a00b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (sample confirmed by Fortinet). Behavioral signatures include creation of the scheduled task “RuntimeBroker,” outbound HTTPS traffic to domains mimicking legitimate services (e.g., “cdn- api[.]cloudflare[.]work”), and User-Agent strings such as “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) RustHttp/1.0.” Registry key modifications occur under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence.
☠️ Risk & Impact
The primary impact is data exfiltration of sensitive intellectual property and credentials, potentially leading to intellectual property theft and espionage. Financial losses from associated remediation and incident response are estimated at $2–5 million per incident based on CrowdStrike’s analysis of two affected defense contractors. Most impacted sectors include defense, telecommunications, and government agencies.
🛡️ Mitigation
Defenders should apply patches for CVE-2023-38831, deploy endpoint detection rules for the “RuntimeBroker” scheduled task and PowerShell reflective loading, and enforce application control policies that block unsigned DLL sideloading. Fortinet recommends network-level filtering of the C2 domain patterns and User-Agent strings listed in indicators.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.