#Thiefbucket
Malware/Tool
Thiefbucket, also known to some researchers as Rustdoor, is stage-two malware associated by Jamf Threat Labs with ongoing DPRK activity. It is delivered by a fake coding challenge in two nearly identical executable forms with different embedded configurations. VisualStudioHelper communicates with wiresapplication[.]com and persists through cron, while zsh_env acts as a backdoor, uses juchesoviet48[.]com for command and control, and persists through the zshrc file. Reported capabilities include automated information theft, Spotlight-based file searches, shell-command execution, file and directory deletion, dialog prompts, self-deletion, and persistence through LaunchAgent, cron, the Dock, or zshrc profiles. Newer samples appear rewritten from Rust in Objective-C.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days