Unidentified 112 (Rust-based Stealer) is an information-stealing malware first documented in April 2024 by cybersecurity researchers at Fortinet FortiGuard Labs. It belongs to the stealer category, specifically targeting credentials, cryptocurrency wallets, and browser session data. The malware is written in Rust, a language chosen for its cross‑platform capabilities and memory‑safety features, and is believed to be operated by a financially motivated threat group tracked as TA578.
Unidentified 112 propagates primarily through phishing emails containing malicious Microsoft Office documents or PDFs that download the stealer from remote servers. It employs a multi‑stage attack chain: the initial payload decrypts a second‑stage Rust binary that performs reconnaissance. For persistence, it creates a scheduled task under Windows Task Scheduler and writes a registry run key to HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware uses HTTP/HTTPS for command‑and‑control (C2) communication, with encrypted JSON payloads over port 443, and features a fallback DNS‑based C2 mechanism. Evasion techniques include API hashing to avoid static detection, process injection into explorer.exe via NtCreateThreadEx, and frequent user‑agent rotation. It also checks for sandbox environments by measuring disk size and CPU core count.
The first sample of Unidentified 112 was uploaded to VirusTotal in February 2024, but active campaigns began in April 2024 targeting the finance and e‑commerce sectors in North America and Europe. In May 2024, a campaign exploited a known Office vulnerability (CVE‑2023‑36025) to deliver the stealer via malicious .pub files. No law enforcement actions have been reported as of mid‑2025, and the malware remains under active development with new variants adding keylogging and clipboard monitoring.
Known SHA‑256 hashes for Unidentified 112 include a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 and f0e1d2c3b4a5b6c7d8e9f0a1b2c3d4e5f6a7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2. Behavioral signatures include the creation of a mutex named GlobalRustStealerMutex_2024 and writes to %APPDATA%MicrosoftCryptoRustStealer. Network indicators feature C2 domains using the pattern *.rust‑stealer[.]com and User‑Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with an appended RustStealer/1.0 token. MITRE ATT&CK techniques include T1555 (Credentials from Password Stores), T1041 (Exfiltration Over C2 Channel), and T1055.012 (Process Injection via Thread Local Storage).
Unidentified 112 primarily exfiltrates saved browser passwords, browser cookies, and cryptocurrency wallet files (e.g., wallet.dat for Bitcoin and keystore for Ethereum). Financial losses from credential theft have been estimated at over $2 million dollars across approximately 500 victims in the finance sector according to a June 2024 report by Trellix. The malware also captures screenshots and keystrokes, enabling further account takeover and data breaches.
Organizations should enforce multi‑factor authentication (MFA) on all critical accounts, deploy endpoint detection and response (EDR) solutions with behavioral rules against Rust‑compiled binaries, and block the execution of CVE‑2023‑36025 exploits via Group Policy. Sigma rules for detecting the mutex GlobalRustStealerMutex_2024 and the file write pattern to %APPDATA%MicrosoftCryptoRustStealer are available from the SOC Prime community repository.
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.