BlueNoroff APT group targets macOS with ‘RustBucket’ Malware
2023-04-21 • Jamf •
https://www.jamf.com/blog/bluenoroff-apt-targets-macos-rustbucket-malware/
Jamf Threat Labs identified RustBucket, a macOS malware family suspected to be linked to North Korean state-sponsored activity and likely BlueNoroff, a Lazarus subgroup. The campaign used an unsigned AppleScript dropper named Internal PDF Viewer.app to download a second-stage PDF-viewer application from attacker infrastructure such as cloud.dnx.capital. The second stage only triggered malicious behavior when opened with a matching weaponized PDF, then decrypted and displayed a decoy venture-capital document while preparing communication with a C2 server for additional payload execution. Jamf noted the workflow and social-engineering pattern aligned with previously reported BlueNoroff activity against cryptocurrency and investment targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9ca914b1cfa8c0ba021b9e00bda71f3… | 2023-04-21 | 2026-04-01 |
| HASH | 3d41cd5199dbd6cefcc78d53bb44a2e… | 2023-04-21 | 2024-01-01 |
| HASH | 9525f5081a5a7ab7d35cf2fb2d7524e… | 2023-04-21 | 2023-07-05 |
| HASH | 7e2b38decf1f826fbb792d762d9e6a2… | 2023-04-21 | 2023-07-05 |