RustyClaw
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:48
- Modified
- 27/05/2026 21:40
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 38 attack patterns (mitre), 1 intrusion sets (apt), 7 sectors, 12 countries, 99 indicators, 21 vulnerabilities (cve), 4 reports
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (38)
-
T1071.001 usesWeb Protocols MITRE
-
T1016 usesSystem Network Configuration Discovery MITRE
-
T1003 usesOS Credential Dumping MITRE
-
T1203 usesExploitation for Client Execution MITRE
-
T1204 usesUser Execution MITRE
-
T1135 usesNetwork Share Discovery MITRE
-
T1587.001 usesMalware MITRE
-
T1210 usesExploitation of Remote Services MITRE
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1569 usesSystem Services MITRE
-
T1102.002 usesBidirectional Communication MITRE
-
T1560 usesArchive Collected Data MITRE
Intrusion sets (APT) (1)
-
UAT-5647 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (7)
-
Telecommunications targets
-
Government targets
-
Finance targets
-
Defense targets
-
Technology targets
-
Logistics targets
-
Manufacturing targets
Countries (12)
-
United States of America targets
-
Germany targets
-
Poland targets
-
British Indian Ocean Territory targets
-
Australia targets
-
Ukraine targets
-
Singapore targets
-
United Kingdom of Great Britain and Northern Ireland targets
-
Kenya targets
-
Canada targets
-
Netherlands targets
-
India targets
Indicators (99)
-
stix 100/100 Revoked· Valid until 20/09/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 14/10/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 14/10/2025 · Source: AlienVault
Vulnerabilities (CVE) (21)
Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload …
- Attack vector
- Network
- Published
- 18/08/2025
- Modified
- 27/05/2026
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to …
- Attack vector
- Network
- Published
- 14/08/2025
- Modified
- 27/05/2026
Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.
- Attack vector
- Network
- Published
- 25/08/2025
- Modified
- 27/05/2026
Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary …
- Attack vector
- NETWORK
- Complexity
- Low
- Published
- 28/08/2025
- Modified
- 18/06/2026
D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands …
- Attack vector
- Network
- Published
- 05/08/2025
- Modified
- 27/05/2026
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary …
- Attack vector
- Network
- Published
- 12/08/2025
- Modified
- 27/05/2026
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the …
- Published
- 20/12/2025
- Modified
- 27/05/2026
An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS …
- Attack vector
- Network
- Complexity
- High
- Published
- 12/08/2025
- Modified
- 27/05/2026
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured …
- Attack vector
- Network
- Published
- 26/08/2025
- Modified
- 27/05/2026
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through …
- Attack vector
- Network
- Published
- 12/08/2025
- Modified
- 27/05/2026
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
- Attack vector
- Network
- Published
- 13/08/2025
- Modified
- 27/05/2026
D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be …
- Published
- 05/08/2025
- Modified
- 27/05/2026
Reports (4)
-
20 CVEs 12 MITREs 3 Malwares 11 Observables 1 APT
-
2 CVEs 3 Malwares 9 Observables 1 APT
-
19 MITREs 9 Malwares 103 Observables 1 APT
-
9 MITREs 6 Malwares 1 APT