Rubeus
MITRE ATT&CK: S1071 View on attack.mitre.org
Aliases: Rubeus
- First seen
- 2020-01-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 51 (50 malicious)
- Last IoC activity
- 2026-09-01 06:26:14
- Profile updated
- 2026-07-07 12:58:49
Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical
Context
Rubeus is a C# toolset designed for raw Kerberos interaction that has been used since at least 2020, including in ransomware operations.
Recent IoC activity
50 malicious indicators in Maltiverse are attributed to Rubeus (S1071). The 20 most recently updated:
Detection coverage
- 5 YARA rules
- 32 Sigma rules
Malware & tools used
- Kerberoasting (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Silver Ticket (attack-pattern)
- AS-REP Roasting (attack-pattern)
- Golden Ticket (attack-pattern)
Used by threat actors
- 2025 Poland Wiper Attacks (campaign)
- Operation AkaiRyū (campaign)
- Wizard Spider (threat-actor)
Detection rules
- DITEKSHEN_INDICATOR_TOOL_PWS_Rubeus (yara-rule)
- SEKOIA_Hacktool_Rubeus_Strings (yara-rule)
- SEKOIA_Tool_Rubeus_Strings (yara-rule)
- SIGNATURE_BASE_HKTL_NET_GUID_Rubeus (yara-rule)
- FIREEYE_RT_Hacktool_MSIL_Rubeus_1 (yara-rule)
Reports & references
- Mandiant — Kegtap And Singlemalt With A Ransomware Chaser (report)
- Cisco Talos — Uat 8837 (report)
- thedfirreport.com — Ryuks Return (report)
- thedfirreport.com — Ryuk Speed Run 2 Hours To Ransom (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Rubeus (report)
- github.com — Rubeus (report)
- MITRE ATT&CK — S1071 (report)