Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

RustDuck botnet rapidly evolves with migration to Rust

The RustDuck botnet is a rapidly evolving IoT malware that exploits known vulnerabilities, including CVE-2017-17215 (CVSS 8.8), to infect devices like routers, cameras, and exposed servers. Its migration to the Rust programming language enhances its anti-analysis capabilities and binary obfuscation, while it uses strong, rotating encryption for C2 communication. Although not the largest botnet currently, its sophisticated evasion techniques and swift technological advancement pose a significant and growing threat.
Read Full Article →

Malware RustDuck botnet rapidly evolves with migration to Rust July 1, 2026 Share By SC Staff As reported by Security Affairs, QiAnXin XLab researchers are tracking a rapidly evolving botnet named RustDuck, which is transitioning from C to Rust and exhibiting increasingly sophisticated evasion and encryption techniques. RustDuck targets a variety of IoT devices, including routers, cameras, and Android set-top boxes, as well as exposed servers running software like ThinkPHP and Jenkins. It exploits a range of known vulnerabilities, from recent to older ones like CVE-2017-17215. The malware employs advanced anti-analysis measures, including a dynamic weight scoring system to detect sandboxed environments and debuggers. Its communication with command-and-control servers utilizes strong encryption like ChaCha20-Poly1305 and AES-GCM, with keys rotating frequently. The botnet's migration to Rust makes its binaries harder to analyze using traditional tools. While currently not the largest botnet, its swift technological advancement and adaptability warrant significant attention from security professionals. Source: Security Affairs SC Staff Related Malware Attack exploiting SimpleHelp vulnerability deploys novel loader, infostealer Laura French June 30, 2026 The TaskWeaver loader delivers Djinn Stealer, which targets dev credentials and AI tokens. Malware Microsoft dismantles StegoAd campaign using malicious Edge extensions SC Staff June 29, 2026 The StegoAd campaign employed steganography to hide malicious JavaScript within image and font files, making the extensions appear legitimate and functional. Malware Fake tax notices used to deliver remote access malware in India SC Staff June 29, 2026 Attackers are employing sophisticated tactics, hiding malicious code behind convincing government branding and legal references to trick victims into downloading a ZIP archive, according to CYFIRMA. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article