BlueNoroff APT group targets macOS with ‘RustBucket’ Malware

2023-04-21 • Jamf •

https://www.jamf.com/blog/bluenoroff-apt-targets-macos-rustbucket-malware/

Thumbnail for BlueNoroff APT group targets macOS with ‘RustBucket’ Malware

Jamf Threat Labs identified RustBucket, a macOS malware family suspected to be linked to North Korean state-sponsored activity and likely BlueNoroff, a Lazarus subgroup. The campaign used an unsigned AppleScript dropper named Internal PDF Viewer.app to download a second-stage PDF-viewer application from attacker infrastructure such as cloud.dnx.capital. The second stage only triggered malicious behavior when opened with a matching weaponized PDF, then decrypted and displayed a decoy venture-capital document while preparing communication with a C2 server for additional payload execution. Jamf noted the workflow and social-engineering pattern aligned with previously reported BlueNoroff activity against cryptocurrency and investment targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9ca914b1cfa8c0ba021b9e00bda71f3… 2023-04-21 2026-04-01
HASH 3d41cd5199dbd6cefcc78d53bb44a2e… 2023-04-21 2024-01-01
HASH 9525f5081a5a7ab7d35cf2fb2d7524e… 2023-04-21 2023-07-05
HASH 7e2b38decf1f826fbb792d762d9e6a2… 2023-04-21 2023-07-05

Related Actors

Related Reports

« Back