RustDuck: A Rust-Based DDoS Botnet Quietly Building Out Since February

XLab researchers say the two-stage loader is iterating faster than its install base is growing, and that's the interesting part.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a tangle of consumer networking gear — a stacked home router, an IP camera
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • QiAnXin's XLab has tracked RustDuck since February 2026, flagging iteration speed as the main concern rather than current scale.
  • A two-stage design keeps the on-disk footprint small and lets operators swap modules without re-seeding victims.
  • Rust's cross-compilation advantages and sparser detection coverage make triage slower, not the malware more sophisticated.
  • Targets are opportunistic: routers with weak credentials, exposed cameras, unpatched Android TV boxes, and internet-facing servers.
  • XLab has not publicly attributed RustDuck to a named cluster; attribution sits at low confidence.

What is RustDuck and why does it matter?

A Rust-written botnet tracked by QiAnXin's XLab as RustDuck has been pulling consumer routers, IP cameras, Android TV boxes and exposed Linux servers into a DDoS swarm since at least February 2026. The headline number isn't the install base. It's the iteration speed.

XLab analysts describe RustDuck as a two-stage family. A small loader handles initial foothold and persistence on whatever embedded box it lands on, then pulls a second-stage payload for command-and-control and flood logic. The split keeps the on-disk footprint small on memory-constrained devices and lets operators swap modules without re-seeding victims. Builds have shifted noticeably across the year: new architectures added, new C2 protocols swapped in, the Rust toolchain updated between samples. Capability is moving faster than scale.

Target selection looks familiar. Home routers with default or weak credentials, IP cameras exposed to the public internet, Android-based set-top boxes that never see a vendor patch, and internet-facing servers running outdated services. The TTPs overlap with what we've seen from Mirai descendants and the Gafgyt lineage for years, though RustDuck's choice of Rust over C is the obvious break.

Should you worry about Rust-based IoT malware?

Choosing Rust isn't pure hype, but the advantages are narrower than breathless coverage suggests. Cross-compilation to MIPS and ARM is straightforward with cargo. Static linking produces self-contained binaries that survive on minimal embedded userlands. Rust binaries also trip fewer YARA rules and heuristics built around a decade of C-based IoT malware. None of that makes the malware more capable. It just makes triage slower, which is worth taking seriously.

The stated end goal is DDoS-for-hire, consistent with the broader booter ecosystem. We covered two cases in this space on 28 May, including federal charges against a man accused of renting out a denial-of-service botnet. RustDuck's codebase reuses some logic patterns seen in earlier Mirai forks, but shared lineage in IoT botnets is the rule rather than the exception. Treat any overlap claims accordingly, and hold attribution at low confidence until XLab publishes more.

What should defenders do right now?

Defensive guidance is unglamorous and unchanged. Pull management interfaces off the public internet. Rotate default credentials on anything with a web UI. Patch what you can, and segment what you can't. For ISPs and hosters, egress anomaly detection on known DDoS reflection ports remains the cheapest win.

Watch whether RustDuck's operators add credential-stuffing or n-day exploitation to the loader. Right now spread looks opportunistic. If that changes, the growth curve will too.

XLab says it will publish IOCs and a sample hash set as the family stabilises. We'll update when those land.

© 2026 Threat Vectr