{"id":1535,"date":"2026-06-30T20:40:15","date_gmt":"2026-06-30T20:40:15","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1535"},"modified":"2026-06-30T20:40:15","modified_gmt":"2026-06-30T20:40:15","slug":"rustduck-botnet-rebuilds-in-rust-to-hijack-routers-and-servers-for-ddos","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1535","title":{"rendered":"RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi2XzOOqoX4E_CfxUMxd0YAH9MRjvZ8-kBBiVhd2VvCvbie3zla8PA80fO2xZ4Ux3_gmreVKG7ANFrSGpDk1lsURfQZuVVapjqi565oGmkqImmFdiQsQFL5z7V9s7TTkH4KgmGbEFnpdAQz94DrXip4q8Qa-ec9K1B1cmeL3szEBWUq9nX-MWppatyug3A\/s1700-e365\/RustDuck.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A new two-stage malware family called <b>RustDuck <\/b>is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline.<\/p>\n<p>Researchers at QiAnXin&#8217;s\u00a0XLab\u00a0have tracked it since February 2026, and say the real story is not how big it is today, but how fast it is changing.<\/p>\n<p>The end goal is a distributed denial-of-service (DDoS) attack: flooding a target with junk traffic from the infected machines until it buckles.<\/p>\n<p>RustDuck is one more entrant in a crowded field, but it stands out for two reasons. It is being rewritten from the C programming language into Rust, and its newer versions go to unusual lengths to avoid being studied or shut down.<\/p>\n<h2>How it spreads<\/h2>\n<p>RustDuck does not lean on a single clever trick. It sprays a mix of old, well-known weaknesses and hopes one sticks. The first is the oldest in the book: devices left on the internet with weak or default passwords on their remote-login services (Telnet and SSH). Guess the password, walk in.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The second is unpatched device bugs. XLab <a href=\"https:\/\/blog.xlab.qianxin.com\/rustduck-en\/\">says<\/a> RustDuck goes after exposed Android debugging interfaces and flaws in gear from TVT (DVRs and cameras), Ruijie, TP-Link, and ZTE, plus a handful of named, years-old vulnerabilities that still litter the internet:<\/p>\n<p>The third path is web software. RustDuck also targets known holes in ThinkPHP, Jenkins, and Hadoop YARN, which stretches its reach from cheap home hardware to exposed server software.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>XLab counted more than 20 internet addresses spreading the malware, with the busiest at\u00a0176.65.139[.]204.<\/p>\n<h2>What makes it tricky<\/h2>\n<p>RustDuck installs in two stages: a small loader that decrypts and unpacks a heavier core module. That core is where the interesting engineering lives, and it is the part being rewritten in Rust.<\/p>\n<p>Rust binaries are generally tougher for analysts to take apart than the C that has powered device malware for years, and XLab says RustDuck&#8217;s Rust core shows real depth in how it derives its keys, hides from analysis, and talks to its servers. The switch points to active development, not a quick re-skin of leaked code.<\/p>\n<p>The bigger tell is how hard the newer samples work to stay hidden. Before doing anything, RustDuck runs a checklist to decide whether it has landed in a security researcher&#8217;s lab instead of on a real victim&#8217;s device. It looks for analysis tools like Wireshark and gdb, for debuggers attached to its own process, for the fingerprints of a honeypot trap, even for virtual-machine hardware.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEihafeXlSAzzDhfqlB7aNBQrgWRhBtNeKxjS1skZlNPTTxo0qgt9YM4taSc_4ypz7e4hyphenhyphen5O7XaEaYebZ_HtaFMRbyJlYz2xIQtWoh_rkjuIO43iL_IAcRR1TfuGnFFFYswnDKjTX3-kIbQDxHRdJE4iI8kJ1SCNQs7y8kWAFXaTzFb9uKfH-CDSOjafUHA\/s1700-e365\/malware.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEihafeXlSAzzDhfqlB7aNBQrgWRhBtNeKxjS1skZlNPTTxo0qgt9YM4taSc_4ypz7e4hyphenhyphen5O7XaEaYebZ_HtaFMRbyJlYz2xIQtWoh_rkjuIO43iL_IAcRR1TfuGnFFFYswnDKjTX3-kIbQDxHRdJE4iI8kJ1SCNQs7y8kWAFXaTzFb9uKfH-CDSOjafUHA\/s1700-e365\/malware.png\" alt=\"\" border=\"0\" data-original-height=\"816\" data-original-width=\"1312\"\/><\/a><\/div>\n<p>Each hit adds points to a risk score. Cross a threshold, and the malware erases its traces and quits before anyone can watch it run.<\/p>\n<p>Two of those checks stand out. One quietly tries to reach an internet address that is reserved for testing and should never answer; if something replies, RustDuck knows it is inside a fake network built to fool malware, and bails.<\/p>\n<p>Another compares two clocks to catch sandboxes that speed up time to rush malware into showing its hand.<\/p>\n<p>Its communications are locked down to match. RustDuck encrypts its traffic with modern ciphers: <b>ChaCha20-Poly1305<\/b> for the handshake, AES-GCM once it is taking commands. It derives its keys with HKDF-SHA256 and a Curve25519 exchange, rotates them every ten minutes, and dresses the connection up to look like ordinary encrypted web traffic so it blends in.<\/p>\n<p>Once a device checks in, the operators can send a short list of orders: start an attack, stop it, report status, switch to new control servers, or quietly upgrade the malware to a newer build. The control addresses lean on free dynamic-DNS services like\u00a0duckdns.org, which is where the \u00abDuck\u00bb in the name comes from.<\/p>\n<h2>This fits a bigger pattern<\/h2>\n<p>RustDuck is not the first botnet to reach for Rust. In April 2025, Fortinet documented\u00a0<a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/new-rust-botnet-rustobot-is-routed-via-routers\">RustoBot<\/a>, a Rust-based botnet that spread through Totolink and other routers to run DDoS attacks, using the same recipe: cheap routers, a modern language, and flood traffic on demand.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>It also arrives in a brutal year for DDoS. The same kind of botnet, scaled up, has produced the biggest floods on record. AISURU and a cluster of related botnets, more than three million hijacked devices between them, drove attacks near 30 Tbps before a\u00a0US-led operation tore down their infrastructure\u00a0this spring. Next to that, RustDuck is tiny. The worry is the direction it is heading.<\/p>\n<p>One detail worth a second look: RustDuck&#8217;s busiest delivery address,\u00a0176.65.139[.]204, sits in the same small block of addresses as the server behind\u00a0a separate ADB-targeting DDoS botnet\u00a0reported in spring 2026. That could be a coincidence or shared bulletproof hosting, and XLab does not link the two, but the overlap is the kind of thing worth checking.<\/p>\n<h2>What to do<\/h2>\n<p>There is no patch for RustDuck itself, because it is malware, not a single bug. Defense means closing the doors it walks through:<\/p>\n<ul>\n<li>Get remote-management interfaces off the public internet. Turn off Android Debug Bridge, Telnet, and SSH where they are not needed, and never leave them reachable with default passwords.<\/li>\n<li>Patch what you can, replace what you can&#8217;t. CouchDB has fixed releases to upgrade to, but some of these routers are past end-of-life. For the D-Link DIR-823X, CISA&#8217;s advice is to pull it from service rather than wait for a patch that isn&#8217;t coming, and the Totolink maker never answered the disclosure. Unsupported gear has to be replaced, not fixed.<\/li>\n<li>Block the known indicators. XLab&#8217;s report lists the malware&#8217;s file hashes, control domains, and source addresses; feed them into your monitoring.<\/li>\n<\/ul>\n<p>RustDuck is a small botnet wearing the engineering of a serious one. Whether it grows into a real threat or fizzles out, the techniques it is testing, a Rust rewrite and a paranoid hide-from-researchers routine, are the parts other crews are most likely to borrow.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1536,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[192,135,333,2268,873,574,2267,777],"class_list":["post-1535","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-botnet","tag-ddos","tag-hijack","tag-rebuilds","tag-routers","tag-rust","tag-rustduck","tag-servers"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1535","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1535"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1535\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1536"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1535"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1535"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1535"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}