216.73.217.22

Reborn in Rust: Attempt to thwart malware analysis

· Published 26/05/2025 12:59 · Modified 26/05/2025 15:10

Export JSON

Essential information

Published
26/05/2025 12:59
Modified
26/05/2025 15:10
Tags
2025-05-26 asyncrat command and control hardware id plugins remote access trojan reverse engineering rust rustyasyncrat system information tls
Related entities
4 observables, 1 intrusion sets (apt), 11 techniques (mitre), 2 malware

Description

, a known since 2019, has been rewritten in , marking a shift from its original C# implementation. This change aims to complicate efforts due to limited analysis tool support for . The malware retains its core functionality, including plugin installation, code execution, and persistence. It installs via scheduled tasks or temporary directory copying, stores in the registry, and communicates with servers over . The variant supports fewer commands compared to its .NET counterpart, suggesting ongoing development. The malware collects , including , OS details, and antivirus software presence. Debug strings in the samples indicate active development of this version.

External references