# JPCERT/CC releases Rust malware reverse-engineering guide

Published: 2026-03-12 · Severity: medium
Canonical: https://vorant.io/reports/b3aca913-dacb-417c-a693-f6fc05be8d9c/jpcert-cc-releases-rust-malware-reverse-engineering-guide

> JPCERT/CC publishes reverse-engineering research on Rust malware following emergence of threats like SysJoker and BlackCat ransomware variants written in Rust.

JPCERT/CC has released a technical report titled 'Study of Binaries Created with Rust through Reverse Engineering' addressing the growing challenge of analyzing malware written in Rust. The report acknowledges that while Rust is gaining adoption as a memory-safe alternative to C/C++, attackers are increasingly leveraging the language's complexity to hinder reverse engineering efforts. Notable examples include Rust variants of SysJoker and BlackCat ransomware.

The research conducted verification studies using cargo 1.82.0, rustc 1.82.0, and IDA Pro v8.3, compiling test binaries in a Windows MSVC environment. The report is structured as independent study items allowing analysts to reference specific topics of interest rather than requiring sequential reading. Sample programs are included to enable hands-on examination alongside the documentation.

JPCERT/CC anticipates increased attacker adoption of Rust due to its reverse-engineering difficulty and aims to provide the security community with foundational knowledge for analyzing Rust-based threats. The organization is soliciting feedback to improve the research content.

## Mentioned in this report

- Malware: BlackCat, SysJoker

Source reporting: https://blogs.jpcert.or.jp/en/2026/03/rust_research_en.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b3aca913-dacb-417c-a693-f6fc05be8d9c/jpcert-cc-releases-rust-malware-reverse-engineering-guide.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
