Tag: rust
-
Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/
-
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe”¯Commerce and”¯Magento Open Source that has come under active exploitation in the wild.The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.”This update resolves a critical First seen on thehackernews.com…
-
Angriff auf Rust-Paketverzeichnis betrifft Crate mit mehr als 245 Millionen Downloads
Das Rust-Projekt hat bösartige Versionen dreier weitverbreiteter Rust-Pakete aus dem Verzeichnis crates.io entfernt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/angriff-auf-rust
-
North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/
-
North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/
-
North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/
-
Supply-Chain-Angriff: Backdoor in millionenfach geladene Rust Crates eingeschleust
Angreifern ist es gelungen, mehrere populäre Rust Crates mit einer Backdoor-Malware zu verseuchen. Entwickler sollten dringend handeln. First seen on golem.de Jump to article: www.golem.de/news/supply-chain-angriff-backdoor-in-millionenfach-geladene-rust-crates-eingeschleust-2608-212158.html
-
Compromised Rust Crate With 18,000+ Downloads Steals Source Code During Builds
A malicious update to the Rust crate called onering has been discovered, which exfiltrates source code changes from developers’ machines during the build process. Security researchers identified this behavior in version 1.4.1 of the package on June 10, 2026. The onering crate, designed as a high-throughput synchronous queue and channels library, has garnered over 18,000…
-
Hackers compromise Rust crate arrayref to inject malware
First seen on scworld.com Jump to article: www.scworld.com/brief/hackers-compromise-rust-crate-arrayref-to-inject-malware
-
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner First…
-
Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers’ systems during compilation. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/
-
C2Looper v2 Uses GitHub Repositories as Full CommandControl Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver tasks, receive results, maintain beacon records, and host payloads. ThreatLabz identified the malware in July 2026 and assesses, with low-to-medium confidence, that it is delivered through…
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance,…
-
Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS
A cross-platform malware campaign that disguises itself as a legitimate Zoom installer to deploy Overlord, an open-source remote access trojan (RAT), on both macOS and Windows machines. Documented by Jamf, unlike most macOS malware, which typically relies on Go or Rust for cross-platform reach, this campaign’s first-stage downloader, a macOS ARM64 Mach-O binary named ZoomMeetings,…
-
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that First…
-
CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions
A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings expand on earlier research by Huntress and LevelBlue, confirming that CastleLoader remains a central delivery mechanism for multi-stage intrusions while introducing new tooling written in Rust and Golang.…
-
Chaos ransomware deploys browser-based msaRAT to evade network detection
Cisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire command-and-control channel through the victim’s own Chrome or Edge browser. The malware…
-
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or Edge…
-
Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process
Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/cisco-talos-chaos-ransomware-msarat/
-
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments.”LabubaRAT creates a reusable foothold for hands-on activity,” Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. “Once deployed, it can profile the host, First seen on…
-
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments.”LabubaRAT creates a reusable foothold for hands-on activity,” Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. “Once deployed, it can profile the host, First seen on…
-
Jscrambler npm Breach Exposes Developers to Malware
Malware Harvested Cloud Credentials, Source Code and Deployment Tokens. Attackers used a compromised npm publishing credential to release five malicious versions of Jscrambler’s Code Integrity package, deploying a Rust-based infostealer that harvested developer, cloud and AI tool credentials while evolving its delivery methods to evade detection. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/jscrambler-npm-breach-exposes-developers-to-malware-a-32215
-
Silver Fox group uses new Rust-based MODBEACON RAT
First seen on scworld.com Jump to article: www.scworld.com/brief/silver-fox-group-uses-new-rust-based-modbeacon-rat
-
Anthropic buffa Library Zero-Day Lets Attackers Trigger Memory-Amplification DoS
Anthropic’s Rust-based protobuf library, buffa, has been discovered to have a zero-day memory amplification denial-of-service (DoS) vulnerability. This flaw allows attackers to deplete system memory using relatively small inputs. Endor Labs identified the issue through its AI-powered static application security testing (SAST) engine and is now tracked as CVE-2026-55407. This situation underscores how logic flaws…
-
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline.Researchers at QiAnXin’s XLab have tracked it since February 2026, and say the real story is not how big it is today, but…
-
macOS.Gaslight: North Korea-Linked Malware That Tries to Gaslight the Analyst
macOS.Gaslight: DPRK Rust implant for Mac with a prompt injection payload designed to fool AI-based malware analysts. SentinelLabs researchers spotted a Rust-based macOS implant, dubbed macOS.Gaslight, that surfaced in early June after an Apple XProtect update pointed to a VirusTotal sample uploaded on May 22. The binary was undetected by static engines at the time…
-
KuinaExtractor Stealer Targets Browser Data, Crypto Wallets, Roblox, Steam, and Discord
A previously undocumented Rust-based infostealer they call KuinaExtractor, a family that has evolved from a capable early prototype into a hardened, stealth-focused threat now rebranded as “k0to.” Analysis of dozens of samples and function-level code comparisons reveals a clear single-operator lineage, steady feature expansion, and deliberate moves toward concealment rather than new capabilities. The actor’s…
-
DPRK-Linked macOS Implant Uses LaunchAgent Persistence and Python Stealer Module
The binary tracked as macOS.Gaslight as a Rust-based macOS implant and infostealer whose most novel features are analyst-directed prompt injection and a hardened Telegram-based command-and-control (C2) channel. We assess with high confidence that macOS.Gaslight aligns with DPRK-linked macOS activity clustered around BONZAI and AIRPIPE signatures. macOS.Gaslight is ad hoc signed, carries the identifier endpoint-macos-aarch64-5555494492fc075f441637fb9d894913dde3a2ea, and…
-
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst’s artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact.The malware has been codenamed Gaslight owing to this deceptive behavior. It’s been assessed with high…

