ATT&CKSoftwareRustyWater

RustyWater

S9037

Malware.View on attack.mitre.org

About this malware

RustyWater is a Rust-based implant used by MuddyWater. Historically, MuddyWater has used PowerShell-based tools and RustyWater reflects a shift in tooling, demonstrating better techniques for defense evasion and reverse engineering.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1027
Obfuscated Files or Information

RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function.

T1027.013
Encrypted/Encoded File

RustyWater has encrypted all strings in the code using position independent XOR encryption.

T1033
System Owner/User Discovery

RustyWater has gathered the victim machine’s username.

T1036.005
Match Legitimate Resource Name or Location

RustyWater has used reddit.exe as its file name and a Cloudflare logo.

T1055.002
Portable Executable Injection

RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`.

T1071.001
Web Protocols

RustyWater has used the Rust request library for HTTP C2 communication.

T1082
System Information Discovery

RustyWater has gathered the victim machine’s computer name.

T1087.002
Domain Account

RustyWater has gathered the domain membership of the victim machine’s user.

T1106
Native API

RustyWater has used `CreateObject` to instantiate a WScript.Shell Component Object Model (COM) object.  Additionally, RustyWater has used `VirtualAllocEx` and `WriteProcessMemory` to inject shellcode into explorer.exe.

T1132.001
Standard Encoding

RustyWater has encoded collected data with Base64.

T1140
Deobfuscate/Decode Files or Information

RustyWater has used the WriteHexToFile function to transform an embedded hex string to the payload CertificationKit.ini.

T1204.002
Malicious File

RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1518.001
Security Software Discovery

RustyWater has attempted to detect more than 25 antivirus and EDR tools.

T1547.001
Registry Run Keys / Startup Folder

RustyWater has established persistence by adding `C:\ProgramData\CertificationKit.ini` to a Windows startup Registry key or to a Run or RunOnce Registry key.

T1559.001
Component Object Model

RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. CloudSEK_RustyWater_Jan2026 Open source
    Awasthi, P. (2026, January 8). Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant. Retrieved March 19, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.