Rustonotto is a Rust-compiled Windows backdoor associated with the North Korean threat actor APT37, also known as ScarCruft or Reaper. It has been reported in operations pairing a Python loader with a Rust-based HTTP backdoor, indicating a modular intrusion chain in which an initial component deploys or launches the backdoor on victim systems.
Rustonotto is characterized as an HTTP backdoor that exchanges commands and responses using Base64 encoding. This supports post-compromise remote tasking over web protocols while blending command traffic into normal network activity. As a backdoor, it enables continued attacker access to infected hosts and is consistent with espionage-oriented tradecraft historically associated with APT37.
Observed reporting links Rustonotto to Windows-focused campaigns and to spearphishing-driven intrusion scenarios reflected in related detection coverage for malicious Office document execution and uncommon child processes spawned by Office applications. The malware appears in the context of APT37 activity targeting strategically relevant victims, particularly in and around South Korea, although precise victimology for Rustonotto specifically is not fully established from the available information.
High-confidence attribution ties Rustonotto to APT37, a long-running North Korean espionage actor known for targeting government, diplomatic, policy, activist, and other intelligence-relevant entities. Rustonotto fits that broader operational pattern as a stealthy backdoor intended to maintain access and support follow-on actions on compromised Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Windows Office Product Dropped Cab or Inf File ... Spearphishing Attachments, Microsoft MSHTML Remote Code Execution CVE-2021-40444, Compromised Windows Host, APT37 Rustonotto and FadeStealer
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT37 Targets Windows with Rust Backdoor and Python Loader Rustonotto
3 distinct techniques documented for this family, organized by ATT&CK tactic.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based backdoor/tool reportedly used by APT37 against Windows, with a Python loader mentioned in the title.
Associated Analytic Story APT37 Rustonotto and FadeStealer
Associated Analytic Story APT37 Rustonotto and FadeStealer
Associated Analytic Story APT37 Rustonotto and FadeStealer
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.