BlueNoroff APT group targets macOS with ‘RustBucket’ Malware
2023-04-21 • Jamf •
https://www.jamf.com/blog/bluenoroff-apt-targets-macos-rustbucket-malware/
Jamf Threat Labs identified RustBucket, a macOS malware family suspected to be linked to North Korean state-sponsored activity and likely BlueNoroff, a Lazarus subgroup. The campaign used an unsigned AppleScript dropper named Internal PDF Viewer.app to download a second-stage PDF-viewer application from attacker infrastructure such as cloud.dnx.capital. The second stage only triggered malicious behavior when opened with a matching weaponized PDF, then decrypted and displayed a decoy venture-capital document while preparing communication with a C2 server for additional payload execution. Jamf noted the workflow and social-engineering pattern aligned with previously reported BlueNoroff activity against cryptocurrency and investment targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 182760cbe11fa0316abfb8b7b00b63f… | 2023-04-21 | 2026-04-01 |
| HASH | 7e69cb4f9c37fad13de85e91b5a05a8… | 2023-04-21 | 2024-01-01 |
| HASH | ca59874172660e6180af2815c3a42c8… | 2023-04-21 | 2023-07-05 |
| HASH | 0be69bb9836b2a266bfd9a8b93bb412… | 2023-04-21 | 2023-07-05 |