KrustyLoader

First seen
2023-10-01 00:00:00
Malware type
downloader, loader
Profile updated
2026-07-07 13:16:23

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

ELF x64 Rust downloader first discovered on Ivanti Connect Secure VPN after the exploitation of CVE-2024-21887 and CVE-2023-46805. Downloads Sliver backdoor and deletes itself.

Exploited vulnerabilities

  • CVE-2023-46805 (vulnerability)
  • CVE-2024-21887 (vulnerability)
  • CVE-2025-31324 (vulnerability)

Reports & references

  • blog.eclecticiq.com — China Nexus Nation State Actors Exploit Sap Netweaver Cve 2025 31324 To Target Critical Infrastructures (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Krustyloader (report)
  • global.ptsecurity.com — Dragons In Thunder (report)
  • nofix.re — 2024 11 02 Rust Symbs (report)
  • nofix.re — 2024 08 03 Arti Rust (report)
  • synacktiv.com — Krustyloader Rust Malware Linked To Ivanti Connectsecure Compromises (report)

External references