Threat reportMalwareTL-2026-0466

Operation Silent Rotor — Rust-based Spear-Phishing Loader Targeting Eurasian Unmanned Aviation Sector Ahead of Moscow UAV Forum

highACTIVE

Operation Silent Rotor (TL-2026-0466), also tracked as Operation Silent Rotor, is a high-severity malware campaign, first published 2026-05-06. It has no confirmed attribution, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1016, T1027, T1033), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-0466

Threat ID
TL-2026-0466
Also known as
Operation Silent Rotor, Silent Rotor, CAI Partner Loader
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
ESPIONAGE
Target sectors
unmanned-aviation, aerospace, aeronautical-information-services, defense, government, supply-chain
Target regions
Russia, Tajikistan, Central Asia, Middle East, Europe
Detection rules
9
Indicators of compromise
20

Malware and tooling in Operation Silent Rotor

Malware and tooling: Silent Rotor Loader

How Operation Silent Rotor works

SEQRITE Labs disclosed Operation Silent Rotor on 2026-05-06: a targeted spear-phishing campaign delivering a 64-bit Rust Windows loader ("Подтверждение заказа продукции ЦАИ.exe") inside a 'cai partner.zip' archive themed around the XIII Eurasian International Forum 'Unmanned Aviation 2026' (Moscow, 23 April 2026). The loader fingerprints victims via hostname and C: volume serial XOR-combined into a decimal machine ID, exfiltrates JSON over XOR-then-HTTPS POSTs to cdn[.]kleymarket[.]ru:443, then derives an AES-256 key from the first two response values to decrypt and execute a second-stage payload from %USERPROFILE%\Documents or C:\Users\Public\Documents. Targeting and Russian-language lure content focus on UAS/UAV professionals across Russia, Tajikistan, Central Asia, the Middle East and Europe.

Operation Silent Rotor is an active, regionally focused spear-phishing campaign uncovered by SEQRITE Labs and publicly documented on 6 May 2026. The campaign weaponises the XIII Eurasian International Forum 'Unmanned Aviation 2026' — scheduled for Moscow on 23 April 2026 — as a social-engineering pretext to lure Russian-speaking unmanned aviation system (UAS) and aeronautical information services professionals into opening a malicious archive ('cai partner.zip') delivered via spear-phishing email.

The archive contains a 64-bit Rust-compiled Windows loader named 'Подтверждение заказа продукции ЦАИ.exe' ("Confirmation of CAI product order.exe") accompanied by three benign-appearing decoys: 'Certificate of translation.PDF', a Russian-language DOCX confirming a long-term CAICA products order tied to the Unmanned Aviation 2026 forum, and 'summary_order_cai_final.xlsx'. On execution, the loader displays an embedded DOCX decoy to maintain the social-engineering cover while it performs host fingerprinting in the background.

Victim profiling is implemented in pure Rust. The loader resolves GetComputerNameExW for the hostname and GetVolumeInformationW for the C: volume serial number, XOR-combines the two values, converts the result to a decimal string and uses it as a unique machine ID. It then reads the USER, USERDNSDOMAIN, COMPUTERNAME and USERPROFILE environment variables, and walks every active interface via GetAdaptersAddresses to gather IPv4 addresses and DNS server entries. The collected metadata is serialised into JSON with the serde_json crate, XOR-encrypted with a static key, and POSTed over HTTPS to https[:]//cdn[.]kleymarket[.]ru:443 (resolving at the time of analysis to 45.142.36.76 on AS48347 'MTW-AS', Moscow, Russia).

The C2 returns an XOR-encrypted blob whose first two values, after decoding, supply a 256-bit AES key and parameters used to decrypt subsequent blocks of payload. The decrypted second-stage executable is written to disk under %USERPROFILE%\Documents\ or C:\Users\Public\Documents\ as a six-character random file name with a .exe extension, using NtWriteFile, and then launched via CreateProcessA. SEQRITE telemetry shows the operator-controlled domain kleymarket[.]ru was registered roughly nine days prior to analysis and resolved to 45.142.36.76, 92.62.113.232 and 89.108.110.154 — all hosted in Russian infrastructure — strongly suggesting purpose-built tradecraft rather than reuse of existing crimeware infrastructure.

While attribution is currently unconfirmed, the combination of Russian-language lures, regional targeting of Russian-speaking UAS professionals, Russian hosting (MTW-AS), tight thematic timing against a Moscow-hosted UAV forum, and the use of a custom Rust loader with bespoke hybrid XOR/AES-256 cryptography are consistent with state-aligned cyber-espionage tradecraft against the unmanned aviation supply chain. Defenders in the UAS, aerospace and aeronautical-information-services sectors across Russia, Tajikistan, the wider CIS, the Middle East and Europe should treat this as a HIGH-severity, actively exploited intrusion vector and prioritise the published file, network and behavioural IOCs for retrospective hunting and prevention.

MITRE ATT&CK techniques used in TL-2026-0466

Discovery

T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036.004 Masquerade Task or Service; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1106 Native API; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090.001 Proxy: Internal Proxy; T1105 Ingress Tool Transfer; T1573.001 Encrypted Channel: Symmetric Cryptography

Initial Access

T1566 Phishing; T1566.001 Phishing: Spearphishing Attachment

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1587.001 Develop Capabilities: Malware

Affected products and versions in Operation Silent Rotor

  • Microsoft — Windows
    Vulnerable versions: Windows 10 x64; Windows 11 x64; Windows Server 2016+ x64
  • N/A — Unmanned Aviation Systems supply chain (UAS/UAV partner workflows)
    Vulnerable versions: all

Remediation for Operation Silent Rotor

Immediate actions

  • Block the C2 domain kleymarket.ru and subdomain cdn.kleymarket.ru at DNS, web proxy and firewall layers.
  • Block outbound HTTPS to 45.142.36.76, 92.62.113.232 and 89.108.110.154 at perimeter and EDR network controls.
  • Hash-block the six published SHA-256 indicators in EDR/AV (loader, archive variants, and decoy documents).
  • Quarantine any cai partner.zip archive or 'Подтверждение заказа продукции ЦАИ.exe' artefacts seen on email gateways or endpoints.
  • Hunt for unknown 6-character random .exe files written to %USERPROFILE%\Documents\ and C:\Users\Public\Documents\ over the last 60 days.

Workarounds

  • Disable execution from user-writable locations (Documents, Public Documents, Downloads) via AppLocker or WDAC for high-risk roles.
  • Strip executables from inbound .zip attachments via mail-flow rules until investigation is complete.
  • Force web/HTTPS inspection for traffic to newly registered .ru domains less than 30 days old.

Longer-term hardening

  • Deploy behavioural EDR detections for Rust-compiled binaries that combine GetComputerNameExW + GetVolumeInformationW + GetAdaptersAddresses with subsequent HTTPS POST and CreateProcessA on a freshly written executable.
  • Enforce attachment policies that block password-protected and .zip-delivered .exe files at the email gateway for users in UAS, aerospace and government supply-chain roles.
  • Implement application allow-listing or WDAC for C:\Users\Public\Documents and user Documents folders to prevent execution of arbitrary binaries.
  • Mandate phishing-resistant MFA and out-of-band verification for any aviation-forum or partner-procurement correspondence.
  • Add newly registered Russian (.ru) domains to elevated-scrutiny lists in DNS and proxy security stacks for at least 90 days post-registration.

Weaknesses (CWE) in Operation Silent Rotor

CWE-506, CWE-829, CWE-94

Timeline of Operation Silent Rotor

  • C2 domain kleymarket.ru registered approximately 9 days prior to first observed active resolution.
  • cdn.kleymarket.ru observed actively resolving to 45.142.36.76 (AS48347, MTW-AS, Moscow, Russia).
  • XIII Eurasian International Forum 'Unmanned Aviation 2026' held in Moscow — used as the social-engineering pretext for the spear-phishing lure.
  • Initial samples of cai partner.zip and the Rust loader 'Подтверждение заказа продукции ЦАИ.exe' surfaced in SEQRITE telemetry against UAS/UAV-sector targets.
  • Threadlinqs Intelligence opened TL-2026-0466 to track Operation Silent Rotor and coordinate detection, simulation and correlation coverage.
  • SEQRITE Labs published 'Operation Silent Rotor' technical analysis documenting the campaign, IOCs and MITRE mapping.
  • As of 2026-05-29, Operation Silent Rotor remains a live, espionage-motivated Rust-loader spear-phishing campaign against the Eurasian unmanned aviation sector, disclosed by SEQRITE only ~3 weeks prior (2026-05-06) and reported as "currently unfolding." No CVE, no takedown, sinkhole, arrest, or attribution upgrade has been published; purpose-built C2 (kleymarket.ru) and tooling remain undisrupted.

Sources cited for Operation Silent Rotor

Detection coverage for TL-2026-0466

As of 2026-05-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0466 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats