VORANT. Threat Intelligence Sign in Get the full feed

JPCERT/CC releases Rust malware reverse-engineering guide

medium threat

JPCERT/CC publishes reverse-engineering research on Rust malware following emergence of threats like SysJoker and BlackCat ransomware variants written in Rust.

JPCERT/CC has released a technical report titled 'Study of Binaries Created with Rust through Reverse Engineering' addressing the growing challenge of analyzing malware written in Rust. The report acknowledges that while Rust is gaining adoption as a memory-safe alternative to C/C++, attackers are increasingly leveraging the language's complexity to hinder reverse engineering efforts. Notable examples include Rust variants of SysJoker and BlackCat ransomware.

The research conducted verification studies using cargo 1.82.0, rustc 1.82.0, and IDA Pro v8.3, compiling test binaries in a Windows MSVC environment. The report is structured as independent study items allowing analysts to reference specific topics of interest rather than requiring sequential reading. Sample programs are included to enable hands-on examination alongside the documentation.

JPCERT/CC anticipates increased attacker adoption of Rust due to its reverse-engineering difficulty and aims to provide the security community with foundational knowledge for analyzing Rust-based threats. The organization is soliciting feedback to improve the research content.

Mentioned in this report

Malware BlackCatSysJoker

Source reporting: https://blogs.jpcert.or.jp/en/2026/03/rust_research_en.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free