RustDoor and Koi Stealer for macOS Used by North Korea-Linked Threat Actor to Target the Cryptocurrency Sector

2025-02-26 Paloalto Networks

https://unit42.paloaltonetworks.com/macos-malware-targets-crypto-sector/

Thumbnail for RustDoor and Koi Stealer for macOS Used by North Korea-Linked Threat Actor to Target the Cryptocurrency Sector

Unit 42 observed a North Korea-linked macOS campaign targeting job-seeking software developers in the cryptocurrency sector through fake recruiter or employer interactions and malicious development projects. The activity used RustDoor binaries masquerading as legitimate software updates and a previously undocumented macOS Koi Stealer variant impersonating Visual Studio. RustDoor attempted to steal LastPass Chrome extension data, exfiltrate it to visualstudiomacupdate[.]com, download reverse-shell scripts from apple-ads-metric[.]com, and connect to 31.41.244[.]92 over TCP 443. Koi Stealer collected the username, password, hardware UUID, installed applications, browser data, FileZilla files, OpenVPN profiles, Steam data, and cryptocurrency wallet-related files after prompting the victim for administrator credentials. The campaign matters because it shows suspected North Korean operators continuing job-themed social engineering against crypto-sector developers while adapting macOS stealers and evasion techniques.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 5.255.101.148 2025-02-26 2026-01-01
HASH c379f4ab29a49d4bccb232c8551d1b8… 2025-02-26 2025-02-26
HASH 2b8c057cf071bcd548d23bc7d73b4a9… 2025-02-26 2025-02-26
HASH b5119a49830a2044f406645c261e54a… 2025-02-26 2025-02-26
HASH 97abafff549ea21797c135c965c5e4a… 2025-02-26 2025-02-26
HASH a5b7ddd12539ce3e8c08bed5855ddce… 2025-02-26 2025-02-26
HASH 77361f7ef25a0185636a0fc6deff2e9… 2025-02-26 2025-02-26
HASH baa676b671e771bf04b245e648f4951… 2025-02-26 2025-02-26
HASH adde2970b40634e91b9ef8520f8e50e… 2025-02-26 2025-02-26
HASH 8be62324fe5af009c12fb9afc8d4f47… 2025-02-26 2025-02-26
HASH 8f0e2b8b3e07f5761066cb00bc0db10… 2025-02-26 2025-02-26
HASH c42b103b42d7e9817f93cb66716b7bf… 2025-02-26 2025-02-26
HASH 76f96a35b6f638eed779dc127f29a5b… 2025-02-26 2025-02-26
HASH 27fcc3278afbbec44737e9f72666946… 2025-02-26 2025-02-26
HASH b5412375477a180608bf410f5cb36b4… 2025-02-26 2025-02-26
HASH 17064520feaf5804aa725e123b24fd0… 2025-02-26 2025-02-26
HASH a900ec81363358ef26bcdf7827f6091… 2025-02-26 2025-02-26
URL https://visualstudiomacupdate.c… 2025-02-26 2025-02-26
URL https://apple-ads-metric.com/sh… 2025-02-26 2025-02-26
URL https://apple-ads-metric.com/ba… 2025-02-26 2025-02-26
URL https://apple-ads-metric.com 2025-02-26 2025-02-26
URL https://visualstudiomacupdate.c… 2025-02-26 2025-02-26
URL https://apple-ads-metric.com/npm 2025-02-26 2025-02-26
DOMAIN visualstudiomacupdate.com 2025-02-26 2025-02-26
DOMAIN apple-ads-metric.com 2025-02-26 2025-02-26
IPv4 31.41.244.92 2025-02-26 2025-02-26

Related Actors

Related Reports

« Back