DustyHammock is a stealth-oriented backdoor associated with RomCom-linked activity and campaigns attributed to the Russia-linked cluster TA829. First identified in 2024, it has been used in intrusion chains targeting primarily organizations in Ukraine and Poland, with activity tied to espionage, sabotage, and data theft objectives in the broader context of Russian-speaking threat operations.
DustyHammock is designed for long-term command-and-control access on compromised Windows systems. Reported functionality includes initial host reconnaissance, remote command execution through the Windows command interpreter, and the ability to download, place, and execute additional malicious payloads. Its role in observed campaigns is typically as a persistent post-compromise backdoor that enables operators to maintain access, conduct follow-on operations, and support exfiltration or further payload deployment.
The malware has been delivered by intermediate components in the RomCom ecosystem, including the MeltingClaw and RustyClaw downloaders, and has also been discussed alongside ShadyHammock and SingleCamper as part of a broader modular toolchain. DustyHammock has been described as Rust-based, while ShadyHammock is treated as a related variant or companion component in some reporting. Similarities in beaconing structure between DustyHammock and SingleCamper suggest operational commonality in administration infrastructure.
Observed delivery activity around the broader toolchain includes spearphishing and phishing lures, often themed around job applications or document sharing, followed by staged loaders and decoy document execution. Within that ecosystem, DustyHammock functions as the durable backdoor used after initial compromise to support reconnaissance, remote tasking, payload delivery, and data theft while attempting to evade detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...downloaders that deliver the ShadyHammock, DustyHammock, and SingleCamper backdoors.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based core backdoor used for persistent, long-term C2 communications and remote command execution in RomCom espionage operations.
Backdoor for long-term access that communicates with C2, performs reconnaissance, executes arbitrary commands, and downloads or places malicious files. The content says it has been used for data exfiltration, espionage, and sabotage while evading detection.
Backdoor delivered by MeltingClaw/RustyClaw in TA829 intrusions.
DustyHammock is a minimalist backdoor used by TA829 for command execution, downloading and running additional files, and network reconnaissance. It is used as a foothold for further compromise and can facilitate data theft or ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.