Rust-Based InfoStealer Targets Chromium Browsers to Extract Sensitive Data

A new Rust-based information stealer has emerged on the cybersecurity radar, specifically engineered to target Chromium-based browsers in order to extract sensitive user data.

Security researchers have traced recent campaigns distributing this advanced infostealer via phishing emails and compromised websites, underlining a concerning trend in malware development: the adoption of Rust programming language for crafting evasive and potent cyber threats.

Surge in Rust Malware Threats

Unlike traditional malware strains relying mostly on C++ or Python, this infostealer leverages Rust’s cross-platform capabilities, memory safety features, and inherent resistance to reverse engineering.

Analysts note that these characteristics make detection and analysis by traditional antivirus solutions noticeably more challenging.

The malware’s primary objective is the exfiltration of browser-resident data such as stored credentials, cookies, autofill information, and even session tokens, predominantly from popular Chromium-based browsers like Google Chrome, Microsoft Edge, and Brave.

Upon successful infection, the malware scans the victim’s device for key browser storage files, including ‘Login Data’ and ‘Cookies’ databases.

Rust-Based InfoStealer
Zip file sent in reversed bytes to C2 server

Using custom Rust routines, the infostealer decrypts stored credentials and cookies, circumventing local OS protection mechanisms.

Researchers highlight that the use of Rust allows the malware to operate with high stability and speed, further enhancing its stealth and effectiveness.

Focus on Chromium-Based Data Theft

Beyond browser data theft, forensic evidence suggests the malware can enumerate installed applications, gather system metadata, and potentially act as a loader for additional payloads.

The campaigns currently observed typically deliver the Rust infostealer as a disguised document or executable, often utilizing social engineering lures that reference invoices, delivery notifications, or urgent account alerts.

Rust-Based InfoStealer
Some of the fake windows displayed by the loader.

Once executed, it establishes a secure encrypted channel with its command-and-control (C2) infrastructure to transmit harvested information, minimizing the risk of interception.

Despite heightened security awareness, Chromium browsers remain prime targets due to their widespread adoption and rich stores of personal and corporate information.

The infostealer’s modular design suggests ease of adaptation, pointing toward possible future variants targeting other browsers or platforms.

According to the Report, Security experts caution organizations to enforce strict endpoint protection policies, maintain up-to-date browser versions, and educate users about the risks of unsolicited attachments and phishing links.

The continued evolution of info-stealing malware, especially those built with resilient languages like Rust, poses a significant challenge to defenders.

Incident responders are urged to monitor for unusual browser file access patterns, outbound traffic to known malicious endpoints, and indicators of compromise (IoCs) associated with this malware family.

Enhanced behavioral analytics, credential vaulting solutions, and prompt patch management can mitigate the risk posed by such advanced threats.

Indicators of Compromise (IOC)

TypeIndicator or Description
File Hashe1a4a3d83c9f4d8e5b77acfc2a2a5a98a4deaad7
C2 Domainruststealer-c2[.]com
C2 IP185.234.219.110
File NameInvoice_2025-06-06.exe
Browser FilesAccess to Login Data, Cookies, Web Data files
Network PatternEncrypted outbound traffic over uncommon ports (e.g., 8082)

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Update

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories