BlueNoroff | How DPRK’s macOS RustBucket Seeks to Evade Analysis and Detection

2023-07-05 Sentinel One

https://www.sentinelone.com/blog/bluenoroff-how-dprks-macos-rustbucket-seeks-to-evade-analysis-and-detection/

Thumbnail for BlueNoroff | How DPRK’s macOS RustBucket Seeks to Evade Analysis and Detection

The RustBucket campaign highlights that the threat actor, whom previous researchers have confidently attributed to DPRK’s BlueNoroff APT, has invested considerable resources in multi-stage malware aimed specifically at macOS users and is evolving its attempts to thwart analysis by security researchers. Back in April, researchers at JAMF detailed a sophisticated APT campaign targeting macOS users with multi-stage malware that culminated in a Rust backdoor capable of downloading and executing further malware on infected devices. ‘RustBucket’, as they labeled it, was attributed with strong confidence to the BlueNoroff APT, generally assumed to be a subsidiary of the wider DPRK cyber attack group known as Lazarus. As the known C2s were unresponsive by the time we conducted our analysis, we were unable to obtain a sample of the next stage of the malware, but already at this point in the operation the malware has gathered a great deal of host information, enabled persistence and opened up a backdoor for further malicious activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 182760cbe11fa0316abfb8b7b00b63f… 2023-04-21 2026-04-01
HASH 7e69cb4f9c37fad13de85e91b5a05a8… 2023-04-21 2024-01-01
HASH 831dc7bc4a234907d94a889bcb60b7b… 2023-07-05 2023-07-05
HASH 5304031dc990790a26184b05b3019b2… 2023-07-05 2023-07-05
HASH 7f8f43326f1ce505a8cd9f469a2ded8… 2023-07-05 2023-07-05
HASH 89301dfdc5361f1650796fecdac30b7… 2023-07-05 2023-07-05
HASH 3cc19cef767dee93588525c74fe9c1f… 2023-07-05 2023-07-05
HASH 5933f1a20117d48985b60b10b5e4241… 2023-07-05 2023-07-05
HASH ed4f16b36bc47a701814b63e30d8ea7… 2023-07-05 2023-07-05
HASH d9f1392fb7ed010a0ecc4f819782c17… 2023-07-05 2023-07-05
HASH 0df7e1d3b3d54336d986574441778c8… 2023-07-05 2023-07-05
HASH 72167ec09d62cdfb04698c3f96a6131… 2023-07-05 2023-07-05
HASH 7a5d57c7e2b0c8ab7d60f7a7c7f4649… 2023-07-05 2023-07-05
HASH d5971e8a3e8577dbb6f5a9aad248c84… 2023-07-05 2023-07-05
HASH 8e7b4a0d9a73ec891edf5b2839602cc… 2023-07-05 2023-07-05
HASH 69f24956fb75beb9b93ef974d873914… 2023-07-05 2023-07-05
HASH dabb4372050264f389b8adcf2393668… 2023-07-05 2023-07-05
HASH ac08406818bbf4fe24ea04bfd72f747… 2023-07-05 2023-07-05
HASH 9121509d674091ce1f5f30e9a372b5d… 2023-07-05 2023-07-05
HASH e7158bb75adf27262ec3b0f2ca73c80… 2023-07-05 2023-07-05
HASH 963a86aab1e450b03d51628797572fe… 2023-07-05 2023-07-05
HASH 27b101707b958139c32388eb4fd79fc… 2023-07-05 2023-07-05
HASH a7f5bf893efa3f6b489efe24195c05f… 2023-07-05 2023-07-05
HASH 9676f0758c8e8d0e0d203c75b922bcd… 2023-07-05 2023-07-05
HASH fd1cef5abe3e0c275671916a1f3a566… 2023-07-05 2023-07-05
HASH b02922869e86ad06ff6380e8ec0be8d… 2023-07-05 2023-07-05
HASH 469236d0054a270e117a2621f70f2a4… 2023-07-05 2023-07-05
HASH a1a85cba1bc4ac9f6eafc548b1454f5… 2023-07-05 2023-07-05
HASH 338af1d91b846f2238d5a518f951050… 2023-07-05 2023-07-05
HASH cd8f41b91e8f1d8625e076f0a161e46… 2023-07-05 2023-07-05
HASH acf1b5b47789badb519ff60dc93afa9… 2023-07-05 2023-07-05
HASH 9a5f6a641cc170435f52c6a759709a6… 2023-07-05 2023-07-05
HASH 8a1b32ab8c2a889985e530425ae00f4… 2023-07-05 2023-07-05
HASH b74702c9b82f23ebf76805f1853bc72… 2023-07-05 2023-07-05
HASH be234cb6819039d6a1d3b1a205b9f74… 2023-07-05 2023-07-05
HASH 0738687206a88ecbee176e05e0518ef… 2023-07-05 2023-07-05
HASH 7e1870a5b24c78a5e357568969aae3a… 2023-07-05 2023-07-05
HASH e2bcdfbda85c55a4d6070c18723ba4a… 2023-07-05 2023-07-05
HASH 7f9694b46227a8ebc67745e533bc0c5… 2023-07-05 2023-07-05
HASH 574bbb76ef147b95dfdf11069aaaa90… 2023-07-05 2023-07-05
DOMAIN crypto.hondchain.com 2023-06-29 2023-07-05
HASH e0e42ac374443500c23672134161286… 2023-04-27 2023-07-05
HASH ca59874172660e6180af2815c3a42c8… 2023-04-21 2023-07-05
HASH 0be69bb9836b2a266bfd9a8b93bb412… 2023-04-21 2023-07-05

Related Actors

Related Reports

« Back