RustoBot is a Rust-based Linux/ELF botnet malware family used primarily for distributed denial-of-service attacks. The content consistently describes it as targeting internet-exposed routers, especially TOTOLINK devices, and also DrayTek routers. Fortinet reported propagation through command-injection and remote-code-execution flaws in TOTOLINK devices, specifically CVE-2022-26210 and CVE-2022-26187 in cstecgi.cgi, and DrayTek CVE-2024-12987 in /cgi-bin/mainfunction.cgi/apmcfgupload. Affected TOTOLINK models mentioned include N600R, A830R, A3100R, A950RG, A800R, A3000RU, and A810R; affected DrayTek models include Vigor2960 and Vigor300B.
After exploitation, RustoBot is delivered via downloader scripts fetched with wget or tftp and supports multiple architectures including arm5, arm6, arm7, mips, mpsl, and x86, with observed payloads often targeting TOTOLINK devices via the mpsl architecture. The malware is obfuscated with XOR-based encryption and uses Global Offset Table manipulation to hinder reverse engineering. It resolves command-and-control domains including dvrhelper[.]anondns[.]net; one report states its C2 domains point to 5.255.125[.]150. Separate reporting tied a RustoBot sample to domains ilefttotolinkalone.anondns[.]net, rustbot.anondns[.]net, bitcoinbandit.anondns[.]net, cryptoenjoyers.anondns[.]net, and dontblockme.anondns[.]net, resolving to 45.137.201[.]137. The malware also uses DNS-over-HTTPS to determine the infected device’s public IP before receiving tasking.
Its core capability is DDoS. The content explicitly attributes UDP flood, TCP flood, and Raw IP flood functionality to RustoBot, with C2 instructions including attack method, target IP/port, duration, and packet length. Fortinet said victims were primarily in the technology sector across Japan, Taiwan, Vietnam, and Mexico. Other reporting states RustoBot was also deployed post-exploitation in attacks against Russian organizations via exploitation of React2Shell (CVE-2025-55182), affecting insurance, e-commerce, and IT entities. In those cases, attackers downloaded an ELF executable named bot from 176.117.107[.]154, identified as RustoBot.
The content also states that RustoBot can embed XMRig as a secondary payload, indicating monetization beyond DDoS. High-confidence indicators mentioned in the content include 176.117.107[.]154, 45.137.201[.]137, 5.255.125[.]150, and the domains dvrhelper[.]anondns[.]net, ilefttotolinkalone.anondns[.]net, rustbot.anondns[.]net, bitcoinbandit.anondns[.]net, cryptoenjoyers.anondns[.]net, and dontblockme.anondns[.]net.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
React2Shell in Russia: ... In some cases, the final payloads were the Kaiji and Rustobot botnets...
Among the key vulnerabilities used: CVE-2022-26187 (via pingCheck)
FortiGuard analysts noticed a sharp uptick in attack attempts exploiting long-standing vulnerabilities in TOTOLINK’s cstecgi.cgi script... Among the key vulnerabilities used: CVE-2022-26210 (via setUpgradeFW)
Among the key vulnerabilities used: CVE-2024-12987 (affecting DrayTek routers through /cgi-bin/mainfunction.cgi/apmcfgupload)
4 distinct techniques documented for this family, organized by ATT&CK tactic.
This script downloaded the XMRig cryptocurrency miner... The attackers also loaded the d5.sh Bash script onto the compromised host to download the Sliver implant... The attackers employed the check.sh Bash script to download ELF executables (a_x86 / a_x64) from a server.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a prior Rust-based botnet used for DDoS attacks against targets via compromised routers.
Botnet payload deployed alongside other malware following exploitation activity.
Rust-based botnet capable of multiple DDoS flood modes; resolves C2-related domains and can deploy/contain XMRig as a secondary payload for monetization.
Botnet payload delivered post-exploitation in campaigns targeting Russian entities (specific capabilities not detailed in the provided content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.