Close Menu
    What's Hot

    Mark Zuckerberg pushes back against AI job loss fears after Meta’s own layoffs

    Trump Had a Billion-Dollar Windfall After Returning to the White House

    Trans Sports Ruling Puts Pressure on States Without Bans

    Facebook X (Twitter) Instagram
    Trending
    • Mark Zuckerberg pushes back against AI job loss fears after Meta’s own layoffs
    • Trump Had a Billion-Dollar Windfall After Returning to the White House
    • Trans Sports Ruling Puts Pressure on States Without Bans
    • Mexico fans blast horns outside Ecuador hotel the night before World Cup clash | World Cup 2026
    • Beaver Statue Honoring the United States Is Smashed in Toronto
    • Trump Officials Sideline Machado, Venezuela’s Opposition Leader, Over Earthquake Response
    • OpenClaw is finally available on Android and iOS
    • Wimbledon: Serena Williams suffers first-round defeat to Maya Joint in much-anticipated first singles match since 2022 | Tennis News
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

    adminBy adminJune 30, 2026No Comments5 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
    Share
    Facebook Twitter LinkedIn Pinterest Email

    RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

    A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline.

    Researchers at QiAnXin’s XLab have tracked it since February 2026, and say the real story is not how big it is today, but how fast it is changing.

    The end goal is a distributed denial-of-service (DDoS) attack: flooding a target with junk traffic from the infected machines until it buckles.

    RustDuck is one more entrant in a crowded field, but it stands out for two reasons. It is being rewritten from the C programming language into Rust, and its newer versions go to unusual lengths to avoid being studied or shut down.

    How it spreads

    RustDuck does not lean on a single clever trick. It sprays a mix of old, well-known weaknesses and hopes one sticks. The first is the oldest in the book: devices left on the internet with weak or default passwords on their remote-login services (Telnet and SSH). Guess the password, walk in.

    Cybersecurity

    The second is unpatched device bugs. XLab says RustDuck goes after exposed Android debugging interfaces and flaws in gear from TVT (DVRs and cameras), Ruijie, TP-Link, and ZTE, plus a handful of named, years-old vulnerabilities that still litter the internet:

    The third path is web software. RustDuck also targets known holes in ThinkPHP, Jenkins, and Hadoop YARN, which stretches its reach from cheap home hardware to exposed server software.

    XLab counted more than 20 internet addresses spreading the malware, with the busiest at 176.65.139[.]204.

    What makes it tricky

    RustDuck installs in two stages: a small loader that decrypts and unpacks a heavier core module. That core is where the interesting engineering lives, and it is the part being rewritten in Rust.

    Rust binaries are generally tougher for analysts to take apart than the C that has powered device malware for years, and XLab says RustDuck’s Rust core shows real depth in how it derives its keys, hides from analysis, and talks to its servers. The switch points to active development, not a quick re-skin of leaked code.

    The bigger tell is how hard the newer samples work to stay hidden. Before doing anything, RustDuck runs a checklist to decide whether it has landed in a security researcher’s lab instead of on a real victim’s device. It looks for analysis tools like Wireshark and gdb, for debuggers attached to its own process, for the fingerprints of a honeypot trap, even for virtual-machine hardware.

    Each hit adds points to a risk score. Cross a threshold, and the malware erases its traces and quits before anyone can watch it run.

    Two of those checks stand out. One quietly tries to reach an internet address that is reserved for testing and should never answer; if something replies, RustDuck knows it is inside a fake network built to fool malware, and bails.

    Another compares two clocks to catch sandboxes that speed up time to rush malware into showing its hand.

    Its communications are locked down to match. RustDuck encrypts its traffic with modern ciphers: ChaCha20-Poly1305 for the handshake, AES-GCM once it is taking commands. It derives its keys with HKDF-SHA256 and a Curve25519 exchange, rotates them every ten minutes, and dresses the connection up to look like ordinary encrypted web traffic so it blends in.

    Once a device checks in, the operators can send a short list of orders: start an attack, stop it, report status, switch to new control servers, or quietly upgrade the malware to a newer build. The control addresses lean on free dynamic-DNS services like duckdns.org, which is where the “Duck” in the name comes from.

    This fits a bigger pattern

    RustDuck is not the first botnet to reach for Rust. In April 2025, Fortinet documented RustoBot, a Rust-based botnet that spread through Totolink and other routers to run DDoS attacks, using the same recipe: cheap routers, a modern language, and flood traffic on demand.

    Cybersecurity

    It also arrives in a brutal year for DDoS. The same kind of botnet, scaled up, has produced the biggest floods on record. AISURU and a cluster of related botnets, more than three million hijacked devices between them, drove attacks near 30 Tbps before a US-led operation tore down their infrastructure this spring. Next to that, RustDuck is tiny. The worry is the direction it is heading.

    One detail worth a second look: RustDuck’s busiest delivery address, 176.65.139[.]204, sits in the same small block of addresses as the server behind a separate ADB-targeting DDoS botnet reported in spring 2026. That could be a coincidence or shared bulletproof hosting, and XLab does not link the two, but the overlap is the kind of thing worth checking.

    What to do

    There is no patch for RustDuck itself, because it is malware, not a single bug. Defense means closing the doors it walks through:

    • Get remote-management interfaces off the public internet. Turn off Android Debug Bridge, Telnet, and SSH where they are not needed, and never leave them reachable with default passwords.
    • Patch what you can, replace what you can’t. CouchDB has fixed releases to upgrade to, but some of these routers are past end-of-life. For the D-Link DIR-823X, CISA’s advice is to pull it from service rather than wait for a patch that isn’t coming, and the Totolink maker never answered the disclosure. Unsupported gear has to be replaced, not fixed.
    • Block the known indicators. XLab’s report lists the malware’s file hashes, control domains, and source addresses; feed them into your monitoring.

    RustDuck is a small botnet wearing the engineering of a serious one. Whether it grows into a real threat or fizzles out, the techniques it is testing, a Rust rewrite and a paranoid hide-from-researchers routine, are the parts other crews are most likely to borrow.

    Botnet DDoS Hijack rebuilds routers rust RustDuck servers
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous Article$22,000 Per Hour: Assistants Use a Legislative Loophole to Outearn Surgeons
    Next Article Wimbledon: Serena Williams suffers first-round defeat to Maya Joint in much-anticipated first singles match since 2022 | Tennis News
    admin
    • Website

    Related Posts

    Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

    June 30, 2026

    Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

    June 30, 2026

    Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses

    June 30, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Mark Zuckerberg pushes back against AI job loss fears after Meta’s own layoffs

    Trump Had a Billion-Dollar Windfall After Returning to the White House

    Trans Sports Ruling Puts Pressure on States Without Bans

    Mexico fans blast horns outside Ecuador hotel the night before World Cup clash | World Cup 2026

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by