REF9135

2023-06-29 • ElasticThe DPRK strikes using a new variant of RUSTBUCKET

Elastic Security Labs used the campaign designator REF9135 for a DPRK-linked intrusion set responsible for a sustained compromise at a cryptocurrency payment services provider, identified through host, binary, and network analysis that tied the activity with high confidence to the Lazarus Group, the DPRK's cybercrime and espionage organization, and specifically to its financially motivated BlueNorOff sub-unit, previously linked to the 2016 Bangladesh Bank SWIFT theft. REF9135 delivered an actively developed variant of the macOS RUSTBUCKET malware via a multi-stage AppleScript, Swift, and Rust loader chain that added a LaunchAgent-based persistence mechanism and evaded VirusTotal signature detection at the time of discovery. Operators rapidly rotated dynamic command-and-control domains and IP infrastructure, some of which shared TLS certificate fingerprints and hosting with infrastructure documented under the DangerousPassword phishing campaign and APT38, to sustain long-term access while frustrating researcher collection efforts.

Related Actors

Related Reports in This Cluster

Top Authors

View REF9135 reports only

View REF9135 reports only