Advertisement
North Korea's Sapphire Sleet Targets Rust Supply Chain via arrayref Crate
North Korean actor Sapphire Sleet compromised a Rust maintainer's account to publish malicious `arrayref` crate versions, targeting the Rust supply chain.
Critical: Rust `arrayref` Crate Poisoned with Infostealer Malware
Hackers compromised `arrayref`, `append-only-vec`, and `internment` Rust crates to inject infostealer malware, impacting developers and downstream projects.
Rust Supply Chain Attack Puts Build-Time Malware in Crates
Compromised maintainer accounts on crates.io pushed malicious Rust crates with build-time malware executing during compilation.
msaRAT: Chaos Ransomware's Covert Browser-Based C2
Cisco Talos uncovers msaRAT, a new Rust-based RAT used by Chaos ransomware for covert C2 via Chrome DevTools Protocol, evading detection.
LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows
Blackpoint Cyber researchers warn of LabubaRAT, a new Rust-based remote access trojan disguised as NVIDIA software, granting full control over Windows hosts.
MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2
A new Rust-based MODBEACON RAT, linked to the Silver Fox cybercrime group, employs gRPC streaming for encrypted C2, propagated via SEO poisoning.
Advertisement
npm Supply Chain Attack: IronWorm and Miasma Malware Analysis
Threat actors target npm developers with the IronWorm info stealer and Miasma worm, utilizing eBPF rootkits to exfiltrate secrets and ensure persistence.
IronWorm: Rust-Written Malware Hits npm Supply Chain Developers
Analysis of the Rust-written IronWorm malware targeting npm supply chain developers.
Microsoft Rust-Based Coreutils for Windows: Security Analysis
Microsoft is adopting Rust-based Coreutils for Windows, offering a memory-safe alternative to legacy GnuWin32 tools. Learn about the security implications.
Microsoft Coreutils for Windows: Security and Memory Safety Analysis
Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.
YARA-X 1.17.0 Release: Enhanced Performance for Malware Analysis
YARA-X version 1.17.0 release introduces five performance improvements and a bugfix for the Rust-based malware detection engine. Enhance your scanning speed.
Fake OpenAI Privacy Filter Repository Distributes Rust Info-Stealer
A malicious Hugging Face repository impersonating OpenAI's privacy tool reached 244k downloads, delivering a Rust-based information stealer to Windows users.
VENON Malware: Rust-Based Banking Trojan Targets Brazilian Banks
A new Rust-based malware called VENON is targeting 33 Brazilian banks with credential-stealing overlays, signaling a shift in Latin American cybercrime TTPs.
Malicious Rust Crates Steal Developer Secrets on Crates.io
Five malicious Rust crates on crates.io masquerade as time utilities to exfiltrate .env files, targeting developer environments and CI/CD pipelines.
YARA-X 1.14.0 Release: Enhanced Performance and Module Stability
The YARA-X 1.14.0 release introduces critical module improvements and bug fixes to optimize high-performance malware scanning and threat detection.