VORANT. Threat Intelligence Sign in Get the full feed

JPCERT publishes Rust malware reverse engineering guide

low threat

JPCERT/CC released a research report detailing techniques for reverse engineering Rust-compiled binaries to aid analysis of growing Rust-based malware.

JPCERT/CC has published a technical report titled "Study of Binaries Created with Rust through Reverse Engineering," addressing a gap in analyst tooling and knowledge as malware authors increasingly adopt Rust. The report notes that Rust variants of known malware families, such as SysJoker and BlackCat ransomware, have appeared in recent years, and that Rust's memory safety and performance benefits are attractive to both legitimate developers and malware authors seeking to complicate reverse engineering efforts.

The research summarizes verification results across multiple independent study items covering Rust binary structure and analysis techniques, using cargo 1.82.0, rustc 1.82.0, and IDA Pro 8.3 in a Windows MSVC compilation environment. The report is structured so analysts can reference individual topics of interest rather than reading sequentially, with sample programs provided for hands-on verification alongside IDA Pro analysis.

This is a defensive research and educational publication rather than a report on active threat activity. JPCERT/CC explicitly anticipates that attacker abuse of Rust will increase given the language's relative reverse-engineering difficulty, and the report is intended to help analysts prepare for and respond to this trend by building foundational Rust reverse-engineering skills.

Mentioned in this report

Malware BlackCatSysJoker

Source reporting: https://blogs.jpcert.or.jp/en/2026/03/rust_research_en.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free