# Operation Silent Rotor — Rust-based Spear-Phishing Loader Targeting Eurasian Unmanned Aviation Sector Ahead of Moscow UAV Forum

> SEQRITE Labs disclosed Operation Silent Rotor on 2026-05-06: a targeted spear-phishing campaign delivering a 64-bit Rust Windows loader ("Подтверждение заказа продукции ЦАИ.exe") inside a 'cai partner.zip' archive themed around the XIII Eurasian International Forum 'Unmanned Aviation 2026' (Moscow, 23 April 2026). The loader fingerprints victims via hostname and C: volume serial XOR-combined into a decimal machine ID, exfiltrates JSON over XOR-then-HTTPS POSTs to cdn[.]kleymarket[.]ru:443, then derives an AES-256 key from the first two response values to decrypt and execute a second-stage payload from %USERPROFILE%\Documents or C:\Users\Public\Documents. Targeting and Russian-language lure content focus on UAS/UAV professionals across Russia, Tajikistan, Central Asia, the Middle East and Europe.

- **Published:** 2026-05-06T12:00:00Z
- **Last reviewed:** 2026-05-06T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0466
- **ID:** TL-2026-0466
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Operation Silent Rotor is an active, regionally focused spear-phishing campaign uncovered by SEQRITE Labs and publicly documented on 6 May 2026. The campaign weaponises the XIII Eurasian International Forum 'Unmanned Aviation 2026' — scheduled for Moscow on 23 April 2026 — as a social-engineering pretext to lure Russian-speaking unmanned aviation system (UAS) and aeronautical information services professionals into opening a malicious archive ('cai partner.zip') delivered via spear-phishing email.

The archive contains a 64-bit Rust-compiled Windows loader named 'Подтверждение заказа продукции ЦАИ.exe' ("Confirmation of CAI product order.exe") accompanied by three benign-appearing decoys: 'Certificate of translation.PDF', a Russian-language DOCX confirming a long-term CAICA products order tied to the Unmanned Aviation 2026 forum, and 'summary_order_cai_final.xlsx'. On execution, the loader displays an embedded DOCX decoy to maintain the social-engineering cover while it performs host fingerprinting in the background.

Victim profiling is implemented in pure Rust. The loader resolves GetComputerNameExW for the hostname and GetVolumeInformationW for the C: volume serial number, XOR-combines the two values, converts the result to a decimal string and uses it as a unique machine ID. It then reads the USER, USERDNSDOMAIN, COMPUTERNAME and USERPROFILE environment variables, and walks every active interface via GetAdaptersAddresses to gather IPv4 addresses and DNS server entries. The collected metadata is serialised into JSON with the serde_json crate, XOR-encrypted with a static key, and POSTed over HTTPS to https[:]//cdn[.]kleymarket[.]ru:443 (resolving at the time of analysis to 45.142.36.76 on AS48347 'MTW-AS', Moscow, Russia).

The C2 returns an XOR-encrypted blob whose first two values, after decoding, supply a 256-bit AES key and parameters used to decrypt subsequent blocks of payload. The decrypted second-stage executable is written to disk under %USERPROFILE%\Documents\ or C:\Users\Public\Documents\ as a six-character random file name with a .exe extension, using NtWriteFile, and then launched via CreateProcessA. SEQRITE telemetry shows the operator-controlled domain kleymarket[.]ru was registered roughly nine days prior to analysis and resolved to 45.142.36.76, 92.62.113.232 and 89.108.110.154 — all hosted in Russian infrastructure — strongly suggesting purpose-built tradecraft rather than reuse of existing crimeware infrastructure.

While attribution is currently unconfirmed, the combination of Russian-language lures, regional targeting of Russian-speaking UAS professionals, Russian hosting (MTW-AS), tight thematic timing against a Moscow-hosted UAV forum, and the use of a custom Rust loader with bespoke hybrid XOR/AES-256 cryptography are consistent with state-aligned cyber-espionage tradecraft against the unmanned aviation supply chain. Defenders in the UAS, aerospace and aeronautical-information-services sectors across Russia, Tajikistan, the wider CIS, the Middle East and Europe should treat this as a HIGH-severity, actively exploited intrusion vector and prioritise the published file, network and behavioural IOCs for retrospective hunting and prevention.

## MITRE ATT&CK

- T1566 Phishing
- T1566.001 Phishing: Spearphishing Attachment
- T1204.002 User Execution: Malicious File
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1106 Native API
- T1036.004 Masquerade Task or Service
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1033 System Owner/User Discovery
- T1083 File and Directory Discovery
- T1071.001 Application Layer Protocol: Web Protocols
- T1090.001 Proxy: Internal Proxy
- T1105 Ingress Tool Transfer
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1041 Exfiltration Over C2 Channel
- T1583.001 Acquire Infrastructure: Domains
- T1587.001 Develop Capabilities: Malware

## Sources

- [Operation Silent Rotor: Targeted Campaign Compromises Unmanned Aviation Sector Ahead of Moscow Summit](https://www.seqrite.com/blog/operation-silent-rotor-rust-malware-unmanned-aviation-sector/)
- [MITRE ATT&CK — T1566.001 Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001/)
- [MITRE ATT&CK — T1071.001 Application Layer Protocol: Web Protocols](https://attack.mitre.org/techniques/T1071/001/)
- [MITRE ATT&CK — T1027 Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027/)
- [MITRE ATT&CK — T1041 Exfiltration Over C2 Channel](https://attack.mitre.org/techniques/T1041/)
- [MITRE ATT&CK — T1204.002 User Execution: Malicious File](https://attack.mitre.org/techniques/T1204/002/)
- [MITRE ATT&CK — T1106 Native API](https://attack.mitre.org/techniques/T1106/)
- [CWE-506: Embedded Malicious Code](https://cwe.mitre.org/data/definitions/506.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0466
