HomeSecurityRustDuck Botnet compromises routers and servers for DDoS

RustDuck Botnet compromises routers and servers for DDoS

A new malware family, dubbed RustDuck, has begun to attract the attention of cybersecurity experts as it targets thousands of connected devices and turns them into part of a botnet capable of launching massive DDoS attacks. While the network is not yet among the largest of its kind, analysts say the speed with which it is evolving is more of a concern than its current size.

Article Image: RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

Researchers at QiAnXin's XLab have been monitoring RustDuck's activity since February 2026 and note that its creators are constantly investing in new techniques to hide and avoid detection. The result is a highly versatile malware that targets both home and corporate infrastructure.

The target is DDoS attacks

As with most botnets, RustDuck's primary purpose is to attacks Distributed Denial of Service (DDoS). Through these attacks, thousands of infected devices simultaneously send a huge volume of requests to a server or online service, causing overload and downtime.

The difference is that RustDuck exploits a wide range of Internet of Things devices, such as routers, IP cameras, Android devices, DVRs , and even exposed Linux servers, creating a highly heterogeneous network of infected systems.

See also: xlabs_v1 Botnet: ADB Exploit for DDoS Attacks on IoT

How it infects devices

RustDuck does not rely on a single vulnerability, but follows a strategy of mass exploitation of known weaknesses.

It initially attempts to gain access through Telnet and SSH services using default or weak passwords, a tactic that still works due to the lack of security on many IoT devices.

It also exploits known vulnerabilities in equipment from companies such as Huawei, D-Link, TP-Link, ZTE, Ruijie and Totolink, as well as security holes in software such as ThinkPHP, Jenkins, Apache CouchDB and Hadoop YARN. The fact that many of these vulnerabilities have been known for years proves that many devices remain without security updates, making them an easy target for attackers.

The transition to Rust is making it difficult for analysts

One of the things that differentiates RustDuck from previous botnets is the gradual abandonment of the C language and the transition to Rust. This programming language is constantly gaining ground in both legitimate software development and the cybercrime space, as it produces more complex binaries that are significantly more difficult for reverse engineering and analysis by security companies.

The malware operates in two stages. First, a small loader, which decrypts and activates the main RustDuck module. This is where all the advanced functionality of the malware.

RustDuck Botnet compromises routers and servers for DDoS

Advanced concealment techniques

RustDuck's creators have incorporated mechanisms reminiscent of malware from advanced cyber-espionage groups. Before starting its operation, the malware checks to see if it is running in an analysis environment. It looks for tools like Wireshark and GDB, checks for virtual machines, sandboxes and honeypots, and even performs time synchronization checks to detect virtual environments that speed up the malware's execution.

If it detects that it is being monitored, it deletes its traces and automatically terminates its operation, making its analysis significantly more difficult.

At the same time, all communication with the control servers is protected with modern encryption algorithms such as ChaCha20-Poly1305, AES-GCM and Curve25519, while the keys change every ten minutes to make it even more difficult to monitor traffic.

See also: Masjesu Botnet: DDoS-for-Hire Service Targets IoT Devices

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Complete control of infected devices

Once the infection is complete, botnet operators can issue remote commands to start or stop DDoS attacks, upgrade the malware, change command-and-control servers, or send information about the device's status.

The control servers use Dynamic DNS services, such as DuckDNS, from which the second part of the name RustDuck comes.

RustDuck Botnet compromises routers and servers for DDoS

A new generation of botnets

The emergence of RustDuck confirms a broader trend in cybercrime. Modern botnets no longer rely solely on a large number of infected devices, but instead invest in sophisticated software engineering, strong encryption, and detection evasion techniques.

It is no coincidence that 2025 was preceded by RustoBot, also written in Rust, while huge botnets like AISURU demonstrated how devastating DDoS attacks can be, reaching even 30 Tbps before being neutralized by international law enforcement operations.

See also: Kimwolf Botnet: Its 23-year-old creator arrested

How can users be protected?

Experts emphasize that the best defense against RustDuck remains proper device management. Disabling services like Telnet, SSH, and Android Debug Bridge when not in use, changing default passwords, and regularly installing security updates significantly reduce the risk of infection.

For older routers that are no longer supported by the manufacturer, the safest option is to replace them. As more and more attacks target IoT devices, outdated equipment easily becomes the weakest link in a network. RustDuck may still be in development, but the techniques it uses clearly point in the direction of next-generation botnets.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS