CVE Tools

RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

The Hacker NewsBy The Hacker News

Our summary

Researchers from QiAnXin XLab report a two-stage malware family called RustDuck that compromises home routers, IP cameras, Android boxes, and exposed servers, then uses the infected devices to launch DDoS attacks. The campaign has been linked to multiple vulnerable products and vulnerabilities, including CVE-2017-17215, CVE-2025-29635, CVE-2024-1781, CVE-2024-1781, CVE-2018-8007, plus exposure to ThinkPHP, Jenkins, and Hadoop YARN issues. The risk is amplified by RustDuck’s active evolution and its use of modern encryption and anti-analysis checks, making detection and takedown harder.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store