KrustyLoader is a Rust-based malware loader with Linux and Windows variants that downloads, decrypts, and executes second-stage payloads, commonly Sliver implants. First publicly documented in January 2024 during compromises of Ivanti Connect Secure appliances, it has also been deployed following exploitation of Ivanti Endpoint Manager Mobile, ConnectWise ScreenConnect, SAP NetWeaver, and Microsoft SharePoint. Deployment frequently involves web shells or scripts on already compromised internet-facing systems, with Amazon S3 storage used to host the loader and subsequent payloads.
KrustyLoader conceals its staging configuration through hexadecimal encoding, XOR transformation, and AES-128-CFB encryption. It decrypts an embedded download URL, retrieves an encrypted payload, and decrypts that payload using embedded cryptographic material. Linux variants write the decrypted payload to a temporary location, grant execution permissions, and launch it. Windows variants decrypt the payload in memory and inject it into Windows Explorer. Evasion measures include execution-location and prerequisite-artifact checks, anti-debugging checks, string obfuscation, and deletion of the loader executable. Windows variants also use relocated and self-deleting copies to remove deployment artifacts.
KrustyLoader is associated with the China-nexus espionage actor UNC5221, also tracked as UTA0178 and QuietCrabs, although not every observed deployment has been conclusively attributed. It has appeared in campaigns targeting government and enterprise environments worldwide, including telecommunications, healthcare, and finance. Its principal role is payload delivery; interactive control, credential theft, lateral movement, and other follow-on operations are performed through Sliver or additional tooling rather than established native loader functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actors were observed using two critical vulnerabilities, CVE-2024-21887 and CVE-2023-46805, for unauthenticated RCE or authentication bypass. The vulnerabilities affect Ivanti Connect Secure (ICS) and Ivanti Policy Secure Gateway devices.
The threat actors were observed using two critical vulnerabilities, CVE-2024-21887 and CVE-2023-46805, for unauthenticated RCE or authentication bypass. The vulnerabilities affect Ivanti Connect Secure (ICS) and Ivanti Policy Secure Gateway devices.
WithSecure detected a threat actor exploiting ScreenConnect and deploying a new Windows variant of the malware dubbed KrustyLoader.
An XML file downloaded from atlas-external.s3.amazonaws[.]com exploits that vulnerability to download KrustyLoader from beansdeals-static.s3.amazonaws[.]com and save it to C:/Windows/Temp/1.exe, before then executing it. | WithSecure detected a threat actor exploiting ScreenConnect and deploying a new Windows variant of the malware dubbed KrustyLoader.
CVE-2025-4427 – Authentication Bypass. These vulnerabilities, when chained, allow unauthenticated attackers to gain full remote command execution on exposed EPMM appliances. | Profero identified a threat group that deployed KrustyLoader on compromised Ivanti EPMM appliances across multiple incident engagements. The loader was dropped to the /tmp directory following successful exploitation of CVE-2025-4427 and CVE-2025-4428.
CVE-2025-4428 – Remote Code Execution. The loader was dropped to the /tmp directory following successful exploitation of CVE-2025-4427 and CVE-2025-4428. | Profero identified a threat group that deployed KrustyLoader on compromised Ivanti EPMM appliances across multiple incident engagements. The loader was dropped to the /tmp directory following successful exploitation of CVE-2025-4427 and CVE-2025-4428.
In the second incident, we found traces of successful exploitation of CVE-2025-53770 within 24 hours of a working exploit being published, and failed attempts within a few hours of the first, non-working exploits appearing.
Vendors additionally document KrustyLoader delivery through exploitation of specific internet-facing vulnerabilities, including the following: SAP NetWeaver (CVE-2025-31324) | KrustyLoader is a downloader that retrieves an encrypted Sliver payload from a second S3 location, injects it into Windows Explorer, and erases itself from disk, leaving the cyber threat actors (CTAs) with immediate covert access to victims’ systems.
Vendors additionally document KrustyLoader delivery through exploitation of specific internet-facing vulnerabilities, including the following: ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708) | KrustyLoader is a downloader that retrieves an encrypted Sliver payload from a second S3 location, injects it into Windows Explorer, and erases itself from disk, leaving the cyber threat actors (CTAs) with immediate covert access to victims’ systems.
Vendors additionally document KrustyLoader delivery through exploitation of specific internet-facing vulnerabilities, including the following: ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708) | KrustyLoader is a downloader that retrieves an encrypted Sliver payload from a second S3 location, injects it into Windows Explorer, and erases itself from disk, leaving the cyber threat actors (CTAs) with immediate covert access to victims’ systems.
UNC5221 was seen abusing a webshell to execute remote commands and fetch from an AWS S3 infrastructure the Rust-based malware loader KrustyLoader, which is typically used for dropping Sliver backdoors.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Both Linux and Windows variants of KrustyLoader have been observed. KrustyLoader, in turn, downloaded the post-exploitation toolkit Sliver.
KrustyLoader is a loader written in Rust. Its primary function is to decrypt a URL pointing to the payload, download that payload, inject it into a target process, and run it.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
It makes the random file executable using system command chmod +x /tmp/randomfile .
“Threat actors use HTTP GET requests, containing Java-based commands… designed to execute external malicious processes… spawning a reverse shell… using /bin/bash”
As a general point, there is a bit of obfuscation: most symbols are XOR-encrypted stack strings. The process of decryption used by the malware to retrieve the URL has three steps... XOR each byte with a 1-byte key; And uses AES-128 CFB-1 mode with hardcoded key and initialization vector to decrypt and get the URL.
KrustyLoader decrypts the payload in memory, injects it into a live explorer.exe process using a dynamically resolved thread-creation function ( RtlCreateUserThread )
KrustyLoader... can make a copy of itself and set itself up to self-delete when its activity is finished...
injects it into Windows Explorer, and erases itself from disk... accessing the URL in a containerized environment produced an automatic file download followed by an immediate self-deletion attempt
“embedded URL… hex string, then XOR encrypted (key: 0x49), and finally encrypted using AES-128 in CFB mode… decrypts… and injects it directly into memory”
KrustyLoader... can carry out various anti-sandbox and anti-analysis checks...
Then the following checks must be validated else the program exits: It gets the process parent ID (PPID) using getppid syscall and exits if PPID is 1... It checks the existence of /tmp/0 and exits if it does not. It checks if its executable (pointed by /proc/self/exe ) is located in /tmp/ directory. If it's not in /tmp/ directory, it exits.
KrustyLoader... can carry out various anti-sandbox and anti-analysis checks...
Then the following checks must be validated else the program exits: It gets the process parent ID (PPID) using getppid syscall and exits if PPID is 1... It checks the existence of /tmp/0 and exits if it does not. It checks if its executable (pointed by /proc/self/exe ) is located in /tmp/ directory. If it's not in /tmp/ directory, it exits.
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based initial-stage malware with Linux and Windows variants that downloads and launches second-stage payloads, often Sliver. Linux deployments targeted Ivanti appliances in late 2023 and early 2024 and were attributed tentatively to UNC5221. Windows deployments followed exploitation of ScreenConnect, with a batch script downloading the loader from a randomly selected predefined AWS S3 URL.
A Rust-based downloader/loader delivered from compromised or attacker-controlled AWS S3 buckets. It decrypts an embedded configuration, retrieves an encrypted second-stage payload, decrypts it in memory, injects it into explorer.exe using RtlCreateUserThread, and self-deletes to reduce forensic artifacts. The campaign is associated in open-source reporting with credential theft and long-term access after exploitation of internet-facing systems.
KrustyLoader is a loader malware used to download and execute additional payloads, such as the Sliver implant, after initial access.
Backdoor/loader deployed against edge networking devices by the QuietCrabs cluster.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.