RustyStealer is a Windows information stealer primarily used to harvest credentials and support follow-on compromise. It can gather information about compromised systems, enumerate files and running processes, support command execution, and deliver additional malware. Observed samples use PowerShell to add Microsoft Defender folder exclusions and establish persistence through RunOnce entries and scheduled tasks. A Rust-compiled launcher variant carries an AES-encrypted payload and persists using legitimate-sounding executable names.
RustyStealer is distributed through Amadey-based pay-per-install operations and has been deployed following attacker-controlled ConnectWise ScreenConnect installations. SilverFox has distributed it using Chinese-language social-engineering lures, including a video-themed executable targeting Chinese-speaking users. Its use has also been associated with the Iranian threat group MuddyWater; these deployment associations do not establish authorship or exclusive ownership.
In a ransomware intrusion in Colombia, RustyStealer infected multiple systems two days before Ymir ransomware deployment. Harvested credentials, including those of a high-privilege account, enabled attackers to move laterally using WinRM and PowerShell. RustyStealer has also been delivered by Lcrypt0rx ransomware, demonstrating its use within multi-stage criminal intrusion chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sample 4: RustyStealer ... This is a Rust-compiled launcher carrying a 5.5 MB AES-encrypted payload.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Lateral movement across the network was facilitated using tools like Windows Remote Management (WinRM) and PowerShell for remote control.
RustyStealer, essentially a credential-harvesting tool, enabled attackers to gain unauthorized access to systems by compromising legitimate high-privilege accounts useful in lateral movement.
MITRE ATT&CK Tactic Technique ID ... Command and Control Application Layer Protocol T1071
MITRE ATT&CK Tactic Technique ID ... Command and Control Multi-Stage Channels T1104
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-compiled stealer/launcher carrying a large AES-encrypted payload. It uses strong encryption, Windows cryptographic APIs, and a persistence disguise system that writes itself to %ProgramData% under one of 20 legitimate-sounding filenames to evade casual forensic review. The campaign describes it as serving the credential theft role in the kill chain.
An information stealer and credential-harvesting tool that can also deliver additional malware.
A newer Rust-based stealer family distributed by the campaign.
RustyStealer is listed as an information stealer distributed in the campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.