RustyRocket is a custom Rust-based malware platform associated with the World Leaks extortion group. It is used primarily as a stealthy data-exfiltration and proxy tool in intrusions focused on data theft and extortion rather than file encryption. The malware has been observed in both Windows and Linux variants and has been described as an in-house capability distributed to World Leaks operators.
RustyRocket is designed to support covert collection and removal of victim data from compromised environments. Reported functionality includes use of SMB to gather files from reachable hosts and exfiltration over HTTPS through heavily obfuscated, multi-layer encrypted tunnels intended to blend malicious traffic into normal network activity. The malware also supports persistence and includes an execution guardrail that requires a pre-encrypted configuration at runtime, complicating analysis and monitoring.
Operational reporting links RustyRocket to World Leaks intrusions in which operators obtained access through exposed infrastructure, stolen credentials, social engineering, and in at least one documented case brute-force access against exposed RDP. After establishing access and moving through the environment, operators deployed RustyRocket on high-value systems such as domain controllers and backup servers to stage and exfiltrate data at scale. World Leaks has targeted organizations across multiple countries and sectors, with healthcare, manufacturing, and business services notably represented. RustyRocket is a key enabling component of the group’s extortion workflow because it facilitates stealthy persistence, internal collection, and large-scale data theft from Windows and Linux enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor then downloaded agent.exe (RustyRocket, first identified and named by Accenture) which is a custom exfiltration platform that World Leaks distributes to their operators.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
In-house data exfiltration tool used by WorldLeaks. The article says it is disguised as a Windows application named winhost.exe, has multiple Windows samples and Linux builds, and is used to steal large victim datasets for extortion operations.
A Rust-based custom exfiltration platform used to index files across the network, collect data over SMB, and transfer it to cloud infrastructure over HTTPS. It supports NORMAL, CLIENT/SERVER, and SERVER modes, accepts credentials for remote share access, and has documented persistence methods and a companion pivoting proxy.
A Rust-written cross-platform (Windows/Linux) malware used by the World Leaks extortion group to maintain persistence, exfiltrate data, and proxy traffic via heavily obfuscated, multi-layer encrypted tunnels. It includes an execution guardrail requiring a pre-encrypted configuration to be provided at runtime, complicating monitoring and detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.