Lazarus Group Uses New RustyAttr Malware for Extended Attribute Abuse to Target macOS – Active IOCs

2024-11-14 Rewterz

https://www.rewterz.com/threat-advisory/lazarus-group-uses-new-rustyattr-malware-for-extended-attribute-abuse-to-target-macos-active-iocs

Thumbnail for Lazarus Group Uses New RustyAttr Malware for Extended Attribute Abuse to Target macOS – Active IOCs

Researchers linked RustyAttr activity to Lazarus with moderate confidence based on tactical and infrastructure overlap with campaigns such as RustBucket. The malware targets macOS by hiding payload retrieval logic in extended file attributes and using Tauri applications signed with a leaked Apple certificate. Execution displays a decoy error message or PDF while malicious JavaScript retrieves the extended attribute content and runs it through a Rust backend. Reported indicators include support.cloudstore.business, support.docsend.site, and multiple hashes, but the source notes no confirmed victims or follow-on payloads.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://filedn.com/lY24cv0Ifefb… 2024-11-13 2025-02-12
DOMAIN filedn.com 2024-11-13 2025-02-12
IPv4 104.168.165.203 2024-07-15 2025-02-12
IPv4 104.168.157.45 2024-07-15 2025-02-12
HASH 78027c3800ff58321371a28b1e2a6d7… 2024-11-14 2025-01-20
HASH 9edbd2f21b81183770fd767b31c2458c 2024-11-14 2024-11-14
HASH 8380d7451f9c4477dd2e8c7c0ba4647… 2024-11-14 2024-11-14
HASH 959e71b8f743a202eb80b65acbb60f7c 2024-11-14 2024-11-14
HASH d8508b3c7ba4f2b9ed1cf3ff28fd6b83 2024-11-14 2024-11-14
HASH 5e38363e7c196a3627dc10a8292bb72… 2024-11-14 2024-11-14
HASH 2efdf82808cd7f63ebc66f553ae9412… 2024-11-14 2024-11-14
HASH 3439de0b221320f58e3432c2672c4074 2024-11-14 2024-11-14
HASH 4a93fe1e7fce91f3c3d99c733d9628e… 2024-11-14 2024-11-14
HASH e9519f91c7acfe68e614fc6d3416033… 2024-11-14 2024-11-14
HASH c91f346d077efbcf45e53e4876b6b23… 2024-11-14 2024-11-14
HASH a26c2442743d234ccd3b0d104e13a798 2024-11-14 2024-11-14
HASH 60be225d1a90070d22bf2abcc740d31… 2024-11-14 2024-11-14
HASH 3d14dd06d85f513dfa96d875fdcc0298 2024-11-14 2024-11-14
HASH 0cbc6df98ce1d302f51714e100560a4d 2024-11-14 2024-11-14
HASH 22a477da55c7391dd0fc6176241d108e 2024-11-14 2024-11-14
HASH 1602cc32d56ab7f7d70c50869613487… 2024-11-14 2024-11-14
HASH a489b72510dfd07e6d05b07e8547cf25 2024-11-14 2024-11-14
HASH 53b68b9304a0462761917608ca4e60e7 2024-11-14 2024-11-14
HASH afefb97605354c96d07d6e24a87798d… 2024-11-14 2024-11-14
HASH 9111d458d5665b1bf463859792e950f… 2024-11-13 2024-11-14
HASH e87177e07ab9651b48664c3d2233424… 2024-11-13 2024-11-14
HASH 7464850d7d6891418c503d0e1732812… 2024-11-13 2024-11-14
HASH 022344029b8bf951ba02b11025fe26c… 2024-11-13 2024-11-14
HASH 176e8a5a7b6737f8d3464c18a77deef… 2024-11-13 2024-11-14
HASH f3e6e8df132155daf1d428dff61f0ca… 2024-11-13 2024-11-14
HASH 48ee5d0d44a015876d867fa515b04c1… 2024-11-13 2024-11-14
HASH 4bce97eff4430708299a1bb4142b9d3… 2024-11-13 2024-11-14
HASH 878e3701df9b0abdaa7094e22d067c8… 2024-11-13 2024-11-14
HASH a4cab67569d0b35c249dc536fb25dab… 2024-11-13 2024-11-14

Related Actors

Related Reports

« Back