Lazarus Group Uses New RustyAttr Malware for Extended Attribute Abuse to Target macOS – Active IOCs

2024-11-14 Rewterz

https://www.rewterz.com/threat-advisory/lazarus-group-uses-new-rustyattr-malware-for-extended-attribute-abuse-to-target-macos-active-iocs

Thumbnail for Lazarus Group Uses New RustyAttr Malware for Extended Attribute Abuse to Target macOS – Active IOCs

Researchers linked RustyAttr activity to Lazarus with moderate confidence based on tactical and infrastructure overlap with campaigns such as RustBucket. The malware targets macOS by hiding payload retrieval logic in extended file attributes and using Tauri applications signed with a leaked Apple certificate. Execution displays a decoy error message or PDF while malicious JavaScript retrieves the extended attribute content and runs it through a Rust backend. Reported indicators include support.cloudstore.business, support.docsend.site, and multiple hashes, but the source notes no confirmed victims or follow-on payloads.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://filedn.com/lY24cv0Ifefb… 2024-11-13 2025-02-12
DOMAIN filedn.com 2024-11-13 2025-02-12
IPv4 104.168.165.203 2024-07-15 2025-02-12
IPv4 104.168.157.45 2024-07-15 2025-02-12
HASH 176e8a5a7b6737f8d3464c18a77deef… 2024-11-13 2025-01-20
HASH 9111d458d5665b1bf463859792e950f… 2024-11-13 2024-11-14
HASH 48ee5d0d44a015876d867fa515b04c1… 2024-11-13 2024-11-14
HASH 022344029b8bf951ba02b11025fe26c… 2024-11-13 2024-11-14
HASH e87177e07ab9651b48664c3d2233424… 2024-11-13 2024-11-14
HASH 878e3701df9b0abdaa7094e22d067c8… 2024-11-13 2024-11-14
HASH 4bce97eff4430708299a1bb4142b9d3… 2024-11-13 2024-11-14
HASH 7464850d7d6891418c503d0e1732812… 2024-11-13 2024-11-14
HASH f3e6e8df132155daf1d428dff61f0ca… 2024-11-13 2024-11-14
HASH a4cab67569d0b35c249dc536fb25dab… 2024-11-13 2024-11-14

Related Actors

Related Reports

« Back