Threat reportMalwareTL-2026-0466
Operation Silent Rotor — Rust-based Spear-Phishing Loader Targeting Eurasian Unmanned Aviation Sector Ahead of Moscow UAV Forum
Operation Silent Rotor (TL-2026-0466), also tracked as Operation Silent Rotor, is a high-severity malware campaign, first published 2026-05-06. It has no confirmed attribution, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1016, T1027, T1033), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-0466
- Threat ID
- TL-2026-0466
- Also known as
- Operation Silent Rotor, Silent Rotor, CAI Partner Loader
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- ESPIONAGE
- Target sectors
- unmanned-aviation, aerospace, aeronautical-information-services, defense, government, supply-chain
- Target regions
- Russia, Tajikistan, Central Asia, Middle East, Europe
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Operation Silent Rotor
Malware and tooling: Silent Rotor Loader
How Operation Silent Rotor works
SEQRITE Labs disclosed Operation Silent Rotor on 2026-05-06: a targeted spear-phishing campaign delivering a 64-bit Rust Windows loader ("Подтверждение заказа продукции ЦАИ.exe") inside a 'cai partner.zip' archive themed around the XIII Eurasian International Forum 'Unmanned Aviation 2026' (Moscow, 23 April 2026). The loader fingerprints victims via hostname and C: volume serial XOR-combined into a decimal machine ID, exfiltrates JSON over XOR-then-HTTPS POSTs to cdn[.]kleymarket[.]ru:443, then derives an AES-256 key from the first two response values to decrypt and execute a second-stage payload from %USERPROFILE%\Documents or C:\Users\Public\Documents. Targeting and Russian-language lure content focus on UAS/UAV professionals across Russia, Tajikistan, Central Asia, the Middle East and Europe.
Operation Silent Rotor is an active, regionally focused spear-phishing campaign uncovered by SEQRITE Labs and publicly documented on 6 May 2026. The campaign weaponises the XIII Eurasian International Forum 'Unmanned Aviation 2026' — scheduled for Moscow on 23 April 2026 — as a social-engineering pretext to lure Russian-speaking unmanned aviation system (UAS) and aeronautical information services professionals into opening a malicious archive ('cai partner.zip') delivered via spear-phishing email.
The archive contains a 64-bit Rust-compiled Windows loader named 'Подтверждение заказа продукции ЦАИ.exe' ("Confirmation of CAI product order.exe") accompanied by three benign-appearing decoys: 'Certificate of translation.PDF', a Russian-language DOCX confirming a long-term CAICA products order tied to the Unmanned Aviation 2026 forum, and 'summary_order_cai_final.xlsx'. On execution, the loader displays an embedded DOCX decoy to maintain the social-engineering cover while it performs host fingerprinting in the background.
Victim profiling is implemented in pure Rust. The loader resolves GetComputerNameExW for the hostname and GetVolumeInformationW for the C: volume serial number, XOR-combines the two values, converts the result to a decimal string and uses it as a unique machine ID. It then reads the USER, USERDNSDOMAIN, COMPUTERNAME and USERPROFILE environment variables, and walks every active interface via GetAdaptersAddresses to gather IPv4 addresses and DNS server entries. The collected metadata is serialised into JSON with the serde_json crate, XOR-encrypted with a static key, and POSTed over HTTPS to https[:]//cdn[.]kleymarket[.]ru:443 (resolving at the time of analysis to 45.142.36.76 on AS48347 'MTW-AS', Moscow, Russia).
The C2 returns an XOR-encrypted blob whose first two values, after decoding, supply a 256-bit AES key and parameters used to decrypt subsequent blocks of payload. The decrypted second-stage executable is written to disk under %USERPROFILE%\Documents\ or C:\Users\Public\Documents\ as a six-character random file name with a .exe extension, using NtWriteFile, and then launched via CreateProcessA. SEQRITE telemetry shows the operator-controlled domain kleymarket[.]ru was registered roughly nine days prior to analysis and resolved to 45.142.36.76, 92.62.113.232 and 89.108.110.154 — all hosted in Russian infrastructure — strongly suggesting purpose-built tradecraft rather than reuse of existing crimeware infrastructure.
While attribution is currently unconfirmed, the combination of Russian-language lures, regional targeting of Russian-speaking UAS professionals, Russian hosting (MTW-AS), tight thematic timing against a Moscow-hosted UAV forum, and the use of a custom Rust loader with bespoke hybrid XOR/AES-256 cryptography are consistent with state-aligned cyber-espionage tradecraft against the unmanned aviation supply chain. Defenders in the UAS, aerospace and aeronautical-information-services sectors across Russia, Tajikistan, the wider CIS, the Middle East and Europe should treat this as a HIGH-severity, actively exploited intrusion vector and prioritise the published file, network and behavioural IOCs for retrospective hunting and prevention.
MITRE ATT&CK techniques used in TL-2026-0466
Discovery
T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036.004 Masquerade Task or Service; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1106 Native API; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090.001 Proxy: Internal Proxy; T1105 Ingress Tool Transfer; T1573.001 Encrypted Channel: Symmetric Cryptography
Initial Access
T1566 Phishing; T1566.001 Phishing: Spearphishing Attachment
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1587.001 Develop Capabilities: Malware
Affected products and versions in Operation Silent Rotor
- Microsoft — Windows
Vulnerable versions: Windows 10 x64; Windows 11 x64; Windows Server 2016+ x64 - N/A — Unmanned Aviation Systems supply chain (UAS/UAV partner workflows)
Vulnerable versions: all
Remediation for Operation Silent Rotor
Immediate actions
- Block the C2 domain kleymarket.ru and subdomain cdn.kleymarket.ru at DNS, web proxy and firewall layers.
- Block outbound HTTPS to 45.142.36.76, 92.62.113.232 and 89.108.110.154 at perimeter and EDR network controls.
- Hash-block the six published SHA-256 indicators in EDR/AV (loader, archive variants, and decoy documents).
- Quarantine any cai partner.zip archive or 'Подтверждение заказа продукции ЦАИ.exe' artefacts seen on email gateways or endpoints.
- Hunt for unknown 6-character random .exe files written to %USERPROFILE%\Documents\ and C:\Users\Public\Documents\ over the last 60 days.
Workarounds
- Disable execution from user-writable locations (Documents, Public Documents, Downloads) via AppLocker or WDAC for high-risk roles.
- Strip executables from inbound .zip attachments via mail-flow rules until investigation is complete.
- Force web/HTTPS inspection for traffic to newly registered .ru domains less than 30 days old.
Longer-term hardening
- Deploy behavioural EDR detections for Rust-compiled binaries that combine GetComputerNameExW + GetVolumeInformationW + GetAdaptersAddresses with subsequent HTTPS POST and CreateProcessA on a freshly written executable.
- Enforce attachment policies that block password-protected and .zip-delivered .exe files at the email gateway for users in UAS, aerospace and government supply-chain roles.
- Implement application allow-listing or WDAC for C:\Users\Public\Documents and user Documents folders to prevent execution of arbitrary binaries.
- Mandate phishing-resistant MFA and out-of-band verification for any aviation-forum or partner-procurement correspondence.
- Add newly registered Russian (.ru) domains to elevated-scrutiny lists in DNS and proxy security stacks for at least 90 days post-registration.
Weaknesses (CWE) in Operation Silent Rotor
Timeline of Operation Silent Rotor
- C2 domain kleymarket.ru registered approximately 9 days prior to first observed active resolution.
- cdn.kleymarket.ru observed actively resolving to 45.142.36.76 (AS48347, MTW-AS, Moscow, Russia).
- XIII Eurasian International Forum 'Unmanned Aviation 2026' held in Moscow — used as the social-engineering pretext for the spear-phishing lure.
- Initial samples of cai partner.zip and the Rust loader 'Подтверждение заказа продукции ЦАИ.exe' surfaced in SEQRITE telemetry against UAS/UAV-sector targets.
- Threadlinqs Intelligence opened TL-2026-0466 to track Operation Silent Rotor and coordinate detection, simulation and correlation coverage.
- SEQRITE Labs published 'Operation Silent Rotor' technical analysis documenting the campaign, IOCs and MITRE mapping.
- As of 2026-05-29, Operation Silent Rotor remains a live, espionage-motivated Rust-loader spear-phishing campaign against the Eurasian unmanned aviation sector, disclosed by SEQRITE only ~3 weeks prior (2026-05-06) and reported as "currently unfolding." No CVE, no takedown, sinkhole, arrest, or attribution upgrade has been published; purpose-built C2 (kleymarket.ru) and tooling remain undisrupted.
Sources cited for Operation Silent Rotor
- Operation Silent Rotor: Targeted Campaign Compromises Unmanned Aviation Sector Ahead of Moscow Summit
- MITRE ATT&CK — T1566.001 Spearphishing Attachment
- MITRE ATT&CK — T1071.001 Application Layer Protocol: Web Protocols
- MITRE ATT&CK — T1027 Obfuscated Files or Information
- MITRE ATT&CK — T1041 Exfiltration Over C2 Channel
- MITRE ATT&CK — T1204.002 User Execution: Malicious File
- MITRE ATT&CK — T1106 Native API
- CWE-506: Embedded Malicious Code
Detection coverage for TL-2026-0466
As of 2026-05-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0466 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.