KrustyLoader
- First seen
- 2023-10-01 00:00:00
- Malware type
- downloader, loader
- Profile updated
- 2026-07-07 13:16:23
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
ELF x64 Rust downloader first discovered on Ivanti Connect Secure VPN after the exploitation of CVE-2024-21887 and CVE-2023-46805. Downloads Sliver backdoor and deletes itself.
Exploited vulnerabilities
- CVE-2023-46805 (vulnerability)
- CVE-2024-21887 (vulnerability)
- CVE-2025-31324 (vulnerability)
Reports & references
- blog.eclecticiq.com — China Nexus Nation State Actors Exploit Sap Netweaver Cve 2025 31324 To Target Critical Infrastructures (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Krustyloader (report)
- global.ptsecurity.com — Dragons In Thunder (report)
- nofix.re — 2024 11 02 Rust Symbs (report)
- nofix.re — 2024 08 03 Arti Rust (report)
- synacktiv.com — Krustyloader Rust Malware Linked To Ivanti Connectsecure Compromises (report)