Lazarus Group Uses New RustyAttr Malware for Extended Attribute Abuse to Target macOS – Active IOCs
2024-11-14 • Rewterz •
Researchers linked RustyAttr activity to Lazarus with moderate confidence based on tactical and infrastructure overlap with campaigns such as RustBucket. The malware targets macOS by hiding payload retrieval logic in extended file attributes and using Tauri applications signed with a leaked Apple certificate. Execution displays a decoy error message or PDF while malicious JavaScript retrieves the extended attribute content and runs it through a Rust backend. Reported indicators include support.cloudstore.business, support.docsend.site, and multiple hashes, but the source notes no confirmed victims or follow-on payloads.
Indicators of Compromise
Related Actors
Related Reports
Shares tags: Lazarus, RustyAttr • Shares 14 IOCs • Published within a week
Shares tag: Lazarus • Same author: Rewterz • Published within a week
Shares tag: Lazarus • Same author: Rewterz • Published within a week
2024-10-24 •
70% Match
Google Chrome Zero-Day Vulnerability Exploited by Lazarus Group by Using Phony DeFi Game – Active IOCs
Rewterz
Shares tag: Lazarus • Same author: Rewterz • Published within a month
2025-02-06 •
60% Match
#Lazarus
Shares tag: Lazarus • Same author: Rewterz
Shares tag: Lazarus • Same author: Rewterz