CargoBay

First seen
2022-01-01 00:00:00
Malware type
trojan, downloader
Family
Malware family
Profile updated
2026-07-07 14:51:36

Targeted industries: technology-and-telecommunications government-and-public-sector financial-services

Context

CargoBay is a newer malware family which was first observed in 2022 and is notable for being written in the Rust language. CargoBay is likely based on source code taken from 'Black Hat Rust' GitHub project (https://github.com/skerkour/black-hat-rust). CargoBay is usually distributed via phishing emails, and the malware binaries may be disguised as legitimate applications. Upon execution, the malware starts by performing environmental checks such as checking its execution path and the configured system language. If the tests pass, then the malware proceeds to gather basic system information and register with its C2 via HTTP from which it receives JSON-formatted jobs to carry out. CargoBay can execute commands via the command line and downloading additional malware binaries.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Cargobay_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Cargobay (report)
  • exchange.xforce.ibmcloud.com — Guid:87Abff769352D8208E403331C86Eb95F (report)

External references