RustDesk is an open-source remote desktop and remote monitoring tool that has been repeatedly abused by intrusion operators and ransomware affiliates as a legitimate-looking remote access channel. In observed compromises, attackers installed standard or custom-compiled RustDesk builds on Windows systems, often as a service, and in some cases modified the application to masquerade as benign remote administration software. Custom variants have been disguised with misleading product branding such as “WinZip Remote Desktop” to reduce suspicion during post-compromise operations.
In malicious operations, RustDesk has primarily been used for post-exploitation rather than initial compromise. Threat actors have deployed it after obtaining access through other means, using it to maintain interactive control of compromised hosts, navigate victim networks, and preserve backup access alongside other persistence mechanisms such as scheduled tasks and service installation. Its use has been documented in ransomware intrusions including activity associated with Akira, where operators leveraged the tool to move through compromised environments and support broader hands-on-keyboard operations. Modified RustDesk instances have also appeared in targeted ransomware incidents involving the emerging Osiris family, where they formed part of a wider toolkit that included credential theft, defense evasion, and data exfiltration.
RustDesk’s appeal to attackers stems from its legitimacy, cross-platform support, and ability to blend into enterprise environments as remote administration software. In the documented abuse cases, it functioned as a stealthy backup channel and persistence mechanism on compromised infrastructure, especially Windows servers. The malicious use of RustDesk reflects a broader trend in which threat actors repurpose legitimate remote management tools to evade detection and sustain access during ransomware and credential-focused intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a victim's machine, building a way back in that did not run through the C2 at all.
The attackers use AnyDesk, Cloudflare Tunnel, RustDesk, Ngrok, and Cloudflare Tunnel to communicate with the command-and-control (C&C).
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access software installed as a Windows service on multiple servers to maintain access during the intrusion.
RustDesk was deployed as a backup remote-access channel to maintain access independent of the primary Havoc C2 path.
RustDesk was used as a custom-compiled remote desktop backdoor and secondary access channel independent of Havoc.
Legitimate remote desktop software referenced as being used in modified form during the campaign, likely to support remote access/persistence prior to ransomware execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.