#RustyAttr

Malware/Tool

2024-11-13 • Stealthy Attributes of APT Lazarus: Evading Detection with Extended Attributes

RustyAttr is a macOS trojan built with the cross-platform Tauri framework. It conceals malicious code in a custom extended attribute named test, abusing filesystem metadata that is normally hidden from Finder and ordinary Terminal directory listings but remains accessible through the xattr utility. The application uses a decoy interface while executing embedded JavaScript through a Tauri webview. Observed samples were signed with a leaked Apple developer certificate that was subsequently revoked, allowing the malware to appear trusted before the certificate was disabled.

Tagged Reports

« Back