Jamf Threat Labs Observes Targeted Attacks Amid FBI Warnings

2024-09-12 Jamf

https://www.jamf.com/blog/jamf-threat-labs-observes-targeted-attacks-amid-fbi-warnings/

Thumbnail for Jamf Threat Labs Observes Targeted Attacks Amid FBI Warnings

Jamf observed DPRK-aligned social engineering against cryptocurrency and developer targets shortly after an FBI warning about North Korean targeting of the crypto sector. In the case described, a LinkedIn recruiter persona sent a zipped Visual Studio coding challenge that hid malicious bash commands inside two csproj files. Building the project used curl to fetch two second-stage Thiefbucket, also known as Rustdoor, payloads from taurihostmetrics.com; the samples communicated with wiresapplication.com and juchesoviet48.com. The payload configurations showed persistence through cron and .zshrc, and one Visual Studio-themed component could prompt for the user password and steal configured files.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 51a88646f9770e09b3505bd5cbadc58… 2024-09-12 2024-09-12
DOMAIN juchesoviet48.com 2024-09-12 2024-09-12
DOMAIN taurihostmetrics.com 2024-09-12 2024-09-12
DOMAIN wiresapplication.com 2024-09-12 2024-09-12
« Back