BlueNoroff APT group targets macOS with ‘RustBucket’ Malware

2023-04-21 Jamf

https://www.jamf.com/blog/bluenoroff-apt-targets-macos-rustbucket-malware/

Thumbnail for BlueNoroff APT group targets macOS with ‘RustBucket’ Malware

Jamf Threat Labs identified RustBucket, a macOS malware family suspected to be linked to North Korean state-sponsored activity and likely BlueNoroff, a Lazarus subgroup. The campaign used an unsigned AppleScript dropper named Internal PDF Viewer.app to download a second-stage PDF-viewer application from attacker infrastructure such as cloud.dnx.capital. The second stage only triggered malicious behavior when opened with a matching weaponized PDF, then decrypted and displayed a decoy venture-capital document while preparing communication with a C2 server for additional payload execution. Jamf noted the workflow and social-engineering pattern aligned with previously reported BlueNoroff activity against cryptocurrency and investment targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 182760cbe11fa0316abfb8b7b00b63f… 2023-04-21 2026-04-01
HASH 7e69cb4f9c37fad13de85e91b5a05a8… 2023-04-21 2024-01-01
HASH ca59874172660e6180af2815c3a42c8… 2023-04-21 2023-07-05
HASH 0be69bb9836b2a266bfd9a8b93bb412… 2023-04-21 2023-07-05

Related Actors

Related Reports

« Back