Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareRansomwareUsed by 1 actor

RustyRocket

RustyRocket is a custom malware platform used by the World Leaks extortion group and first identified and named by Accenture. It is written in Rust and is described as a sophisticated data exfiltration and proxy tool that supports stealthy persistence on victim networks. Accenture reported that it targets both Microsoft Windows and Linux environments, uses heavily obfuscated multi-layer encrypted tunnels to blend malicious traffic into legitimate network activity, and includes an execution guardrail requiring a pre-encrypted configuration at runtime, which makes monitoring and detection more difficult.

In the reported World Leaks intrusion, the actor gained initial access by brute forcing an exposed RDP service using a company-specific wordlist and reused the compromised Administrator credentials to move laterally. On Day 2 of the intrusion, the actor downloaded agent.zip from temp[.]sh to the domain controller, deployed agent.exe to C:\ProgramData\Veeam, and executed it on both the domain controller and backup server. The payload was identified as RustyRocket, with SHA256 743f9dbb32f86322c5f55f1e9051c5cd88092f10adcdac45aa648ac06e229b8a. In that case, RustyRocket ran in NORMAL mode, used SMB over port 445 to collect files from reachable hosts, and exfiltrated data over HTTPS over port 443 to more than 6,900 unique Cloudflare IPs.

RustyRocket is associated with World Leaks’ data-theft-and-extortion operations rather than file encryption. World Leaks has been active since early 2025 and is reported to obtain access through social engineering, stolen credentials, or exploitation of exposed infrastructure. In the cited intrusion, RustyRocket was deployed after the actor had already accessed the domain controller and backup infrastructure, indicating use against high-value enterprise systems and backup environments.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Hunters International

The threat actor then downloaded agent.exe (RustyRocket, first identified and named by Accenture) which is a custom exfiltration platform that World Leaks distributes to their operators.

via breachcachebreachcache.com
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Collection

1 technique
T1039Data from Network Shared DriveEvidence1

The domain controller instance handled the SMB collection connecting to every reachable host across the network over 445 indexing and exfiltrating every file from 10 hosts in 8 minutes.

Command and Control

2 techniques
T1090.003Multi-hop ProxyEvidence1

...enabling affiliates to stealthily exfiltrate data and proxy traffic across victim environments...

T1573Encrypted ChannelEvidence1

...steal data through heavily obfuscated, multi-layered encrypted tunnels. This blends the malicious activity within legitimate network activity.

Exfiltration

2 techniques
T1041Exfiltration Over C2 ChannelEvidence1

RustyRocket malware is described as a “sophisticated data exfiltration and proxy tool” which allows attackers to steal data through heavily obfuscated, multi-layered encrypted tunnels.

T1567Exfiltration Over Web ServiceEvidence1

Both instances transmitted data over 443 to infrastructure sitting behind Cloudflare... connecting to over 6,900 unique Cloudflare IPs across both hosts.

INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app9 days ago
hash.sha256●●●●●●●●●●●●View more in app2 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.