RustDuck Botnet is targeting routers, servers, IP cameras, and Android TV boxes to launch large-scale DDoS attacks. Researchers discovered the malware in early 2026 and found that it continues to evolve rapidly. However, the biggest concern is not its current size but its advanced development. Therefore, security experts urge organizations to strengthen their defenses before the botnet expands further.
RustDuck Uses Multiple Infection Methods
The malware does not rely on a single attack method. Instead, it combines several common techniques to infect as many devices as possible. For example, it scans the internet for devices using weak or default Telnet and SSH passwords. If attackers guess the credentials, they gain immediate access.
However, weak passwords are only one entry point. The malware also exploits outdated software vulnerabilities in routers, cameras, and Android devices. In addition, it targets exposed debugging services and several long-known security flaws. Therefore, organizations that delay updates remain at greater risk.
Researchers also found attacks against web applications and server software. For example, vulnerable systems running outdated frameworks become attractive targets. As a result, the malware can spread from home devices to enterprise servers.
RustDuck Shifts from C to Rust
One of the malware’s most notable changes is its migration from the C programming language to Rust. Researchers believe this change makes the malware harder to analyze. However, the rewrite also shows that the attackers continue to improve their tools.
The malware operates in two stages. First, a lightweight loader enters the system. Next, it decrypts and launches the main malware module. Therefore, security researchers must analyze multiple components before understanding the full attack. Rust also provides stronger memory safety and modern programming features. As a result, attackers can create more reliable malware while making reverse engineering more difficult.
Advanced Evasion Makes Detection Harder
RustDuck includes several techniques that help it avoid security analysis. Before starting its malicious activity, it checks whether researchers are examining it. For example, it searches for debugging software, virtual machines, and network monitoring tools.
However, the malware does not stop there. It also measures system behavior to detect artificial testing environments. If the device appears suspicious, the malware removes traces and exits immediately. Therefore, analysts receive very little evidence during investigations.
The malware even checks internet responses that should never exist. It also compares different system clocks to detect accelerated testing environments. As a result, many automated analysis systems struggle to observe its behavior.
Encrypted Communication Supports Remote Control
Once the malware infects a device, it securely contacts its command server. Researchers found that it uses modern encryption methods to protect these communications. Therefore, network monitoring becomes much more challenging.
Attackers can issue several commands after the connection succeeds. For example, they can launch DDoS attacks, stop operations, update the malware, or change command servers. In addition, the malware regularly rotates encryption keys to improve security.
Researchers also noticed that the malware hides its traffic within normal encrypted internet communications. Consequently, malicious activity blends into legitimate network traffic more easily.
RustDuck Follows a Growing Malware Trend
RustDuck is not the first botnet built with Rust. Researchers previously observed other malware families using the same programming language for similar attacks. However, RustDuck introduces stronger anti-analysis features than many earlier threats.
Security experts also compare this campaign with recent large botnet operations. Some previous botnets controlled millions of compromised devices and generated record-breaking DDoS attacks. Although RustDuck remains much smaller today, researchers believe its rapid development deserves close attention.
The report also identified similarities between RustDuck infrastructure and another botnet campaign. However, researchers have not confirmed any direct connection. Therefore, additional investigation remains necessary.
How to Reduce the Risk
There is no single patch that removes RustDuck because it is malware, not a software bug. Therefore, organizations should focus on reducing attack opportunities. They should disable unused remote services such as Telnet, SSH, and Android Debug Bridge whenever possible. In addition, administrators should replace unsupported devices because many no longer receive security updates.
Organizations should also monitor networks for known malicious indicators and unusual outbound traffic. Regular vulnerability assessments help identify exposed systems before attackers exploit them. Furthermore, continuous security monitoring and incident response services allow security teams to detect suspicious activity early and respond before malware spreads across critical infrastructure.
Sleep well, we got you covered.

