RustyStealer is a Windows information-stealing malware family written in Rust and used to harvest credentials and other sensitive data from compromised systems. It has been observed as both a standalone stealer and a launcher carrying an encrypted payload, and open reporting indicates it can also deliver additional malware. Documented intrusion chains show RustyStealer preceding hands-on-keyboard activity and later-stage ransomware deployment, including cases involving Ymir, where stolen high-privilege credentials enabled unauthorized access and lateral movement through remote administration mechanisms such as WinRM and PowerShell. It has also appeared as a payload in commodity botnet and pay-per-install ecosystems, including Amadey-driven distribution, alongside other stealers and remote access tools.
Operational reporting links RustyStealer to multiple threat contexts. It has been associated with financially motivated malware delivery operations and has also been reported as a tool used by the Iranian state-linked group MuddyWater. In Chinese-language intrusion activity attributed to the SilverFox cluster, RustyStealer has been used with social-engineering lures and persistence under legitimate-sounding executable names. Across these contexts, the malware is consistently characterized as a credential-harvesting infostealer that supports follow-on compromise.
Observed behavior includes collection of credentials and system information, command execution or remote control functionality in some incidents, and use as an access-enabling component for broader post-compromise operations. In ransomware-linked cases, RustyStealer infections were detected before encryption events and were assessed to have facilitated compromise of privileged accounts useful for lateral movement. Technical reporting also notes Rust-compiled launcher variants with AES-encrypted embedded payloads and obfuscation or packing characteristics consistent with evasive delivery tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sample 4: RustyStealer ... This is a Rust-compiled launcher carrying a 5.5 MB AES-encrypted payload.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Lateral movement across the network was facilitated using tools like Windows Remote Management (WinRM) and PowerShell for remote control.
RustyStealer, essentially a credential-harvesting tool, enabled attackers to gain unauthorized access to systems by compromising legitimate high-privilege accounts useful in lateral movement.
MITRE ATT&CK Tactic Technique ID ... Command and Control Application Layer Protocol T1071
MITRE ATT&CK Tactic Technique ID ... Command and Control Multi-Stage Channels T1104
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-compiled stealer/launcher carrying a large AES-encrypted payload. It uses strong encryption, Windows cryptographic APIs, and a persistence disguise system that writes itself to %ProgramData% under one of 20 legitimate-sounding filenames to evade casual forensic review. The campaign describes it as serving the credential theft role in the kill chain.
An information stealer and credential-harvesting tool that can also deliver additional malware.
A newer Rust-based stealer family distributed by the campaign.
RustyStealer is listed as an information stealer distributed in the campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.