BlueNoroff's RustBucket MacOS Malware
2023-05-12 • Poly Swarm •
https://blog.polyswarm.io/bluenoroffs-rustbucket-macos-malware
BlueNoroff used the multistage RustBucket malware to target macOS systems in financially motivated operations. The first stage is an unsigned Internal PDF Viewer.app AppleScript that requires the victim to override Gatekeeper, then retrieves a signed second-stage application masquerading with a legitimate Apple bundle identifier. A malicious PDF acts as the trigger for the next phase, causing the second stage to contact C2 and download a Rust-based Mach-O payload for ARM and x86 systems. The final payload gathers system information and supports additional attacker actions on the victim host, fitting BlueNoroff’s pattern of job-themed lures and financial-sector targeting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | bea33fb3205319868784c028418411e… | 2023-05-12 | 2023-05-22 |
| HASH | 8e234482db790fa0a3d2bf5f7084ec4… | 2023-05-12 | 2023-05-22 |
| HASH | 7981ebf35b5eff8be2f3849c8f3085b… | 2023-05-01 | 2023-05-22 |
| HASH | 3d41cd5199dbd6cefcc78d53bb44a2e… | 2023-05-12 | 2023-05-12 |