Rustock

First seen
2006-01-01 00:00:00
Malware type
botnet
Family
Malware family
Profile updated
2026-07-07 14:50:34

Context

Rustock is a sophisticated botnet malware that was primarily used for sending spam emails. It utilizes rootkit techniques to hide its presence and control infected machines.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Rustock_Auto (yara-rule)

Related threat objects

  • Rustock (infrastructure)

Reports & references

  • web.archive.org — Blackhat Eu 2010 Carrera Silberman State Of Malware Slides (report)
  • darknetdiaries.com — 110 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Rustock (report)
  • blog.threatexpert.com — Rustockc Unpacking Nested Doll (report)
  • drweb.com — 6C5E138F917290Cb99224A8F8226354F 1210062403 Ddocumentsarticales Prdrweb Rustockc Eng (report)
  • contagiodump.blogspot.com — Rustock Samples And Analysis Links (report)
  • secureworks.com — Research 21041 (report)
  • sunbeltsecurity.com — Rootkit%20Installation%20And%20Obfuscation%20In%20Rustock (report)
  • usenix.org — Index (report)
  • krebsonsecurity.com — Microsoft Hunting Rustock Controllers (report)
  • blog.novirusthanks.org — I Wormnuwarw Rustocke Variant Analysis (report)

External references