Rustock
- First seen
- 2006-01-01 00:00:00
- Malware type
- botnet
- Family
- Malware family
- Profile updated
- 2026-07-07 14:50:34
Context
Rustock is a sophisticated botnet malware that was primarily used for sending spam emails. It utilizes rootkit techniques to hide its presence and control infected machines.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Rustock_Auto (yara-rule)
Related threat objects
- Rustock (infrastructure)
Reports & references
- web.archive.org — Blackhat Eu 2010 Carrera Silberman State Of Malware Slides (report)
- darknetdiaries.com — 110 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Rustock (report)
- blog.threatexpert.com — Rustockc Unpacking Nested Doll (report)
- drweb.com — 6C5E138F917290Cb99224A8F8226354F 1210062403 Ddocumentsarticales Prdrweb Rustockc Eng (report)
- contagiodump.blogspot.com — Rustock Samples And Analysis Links (report)
- secureworks.com — Research 21041 (report)
- sunbeltsecurity.com — Rootkit%20Installation%20And%20Obfuscation%20In%20Rustock (report)
- usenix.org — Index (report)
- krebsonsecurity.com — Microsoft Hunting Rustock Controllers (report)
- blog.novirusthanks.org — I Wormnuwarw Rustocke Variant Analysis (report)