#RustDoor
Malware/Tool
2025-02-26 • RustDoor and Koi Stealer for macOS Used by North Korea-Linked Threat Actor to Target the Cryptocurrency Sector
RustDoor is Rust-based malware for macOS observed in a campaign targeting job-seeking software developers in the cryptocurrency sector. It masqueraded as a legitimate software update and appeared alongside a previously undocumented macOS variant of Koi Stealer. Researchers linked the surrounding social-engineering activity to characteristics reported for North Korea-associated threat actors and observed manipulation of macOS components for evasion. The investigation also found distinct command-and-control servers among analyzed samples and noted that a malware file named .zsh_env shared a hash with a previously reported ThiefBucket sample.
-
2
Tagged Reports
-
2
Unique Authors
-
310
Active Days