Jamf Threat Labs Observes Targeted Attacks Amid FBI Warnings
2024-09-12 • Jamf •
https://www.jamf.com/blog/jamf-threat-labs-observes-targeted-attacks-amid-fbi-warnings/
Jamf observed DPRK-aligned social engineering against cryptocurrency and developer targets shortly after an FBI warning about North Korean targeting of the crypto sector. In the case described, a LinkedIn recruiter persona sent a zipped Visual Studio coding challenge that hid malicious bash commands inside two csproj files. Building the project used curl to fetch two second-stage Thiefbucket, also known as Rustdoor, payloads from taurihostmetrics.com; the samples communicated with wiresapplication.com and juchesoviet48.com. The payload configurations showed persistence through cron and .zshrc, and one Visual Studio-themed component could prompt for the user password and steal configured files.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 51a88646f9770e09b3505bd5cbadc58… | 2024-09-12 | 2024-09-12 |
| DOMAIN | juchesoviet48.com | 2024-09-12 | 2024-09-12 |
| DOMAIN | taurihostmetrics.com | 2024-09-12 | 2024-09-12 |
| DOMAIN | wiresapplication.com | 2024-09-12 | 2024-09-12 |