BlueNoroff's RustBucket MacOS Malware

2023-05-12 Poly Swarm

https://blog.polyswarm.io/bluenoroffs-rustbucket-macos-malware

Thumbnail for BlueNoroff's RustBucket MacOS Malware

BlueNoroff used the multistage RustBucket malware to target macOS systems in financially motivated operations. The first stage is an unsigned Internal PDF Viewer.app AppleScript that requires the victim to override Gatekeeper, then retrieves a signed second-stage application masquerading with a legitimate Apple bundle identifier. A malicious PDF acts as the trigger for the next phase, causing the second stage to contact C2 and download a Rust-based Mach-O payload for ARM and x86 systems. The final payload gathers system information and supports additional attacker actions on the victim host, fitting BlueNoroff’s pattern of job-themed lures and financial-sector targeting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bea33fb3205319868784c028418411e… 2023-05-12 2023-05-22
HASH 8e234482db790fa0a3d2bf5f7084ec4… 2023-05-12 2023-05-22
HASH 7981ebf35b5eff8be2f3849c8f3085b… 2023-05-01 2023-05-22
HASH 3d41cd5199dbd6cefcc78d53bb44a2e… 2023-05-12 2023-05-12

Related Actors

Related Reports

« Back