Stealthy Attributes of APT Lazarus: Evading Detection with Extended Attributes
2024-11-13 • Group-IB •
https://www.group-ib.com/blog/stealthy-attributes-of-apt-lazarus/
Group-IB identified a macOS technique attributed with moderate confidence to Lazarus in which malicious code is hidden inside custom extended attributes rather than in visible application files. The RustyAttr trojans were built with Tauri, used JavaScript-to-Rust calls to read an extended attribute named "test," and executed the embedded shell script while showing either a decoy PDF or a fake unsupported-version dialog. The scripts attempted to fetch follow-on content from staging servers such as support.cloudstore[.]business and support.docsend[.]site, and the infrastructure and hosting context overlapped with earlier Lazarus activity including RustBucket-related files. The samples were signed with a leaked certificate later revoked by Apple, were unnotarized, and were undetected on VirusTotal at analysis time, making the extended-attribute smuggling technique notable for macOS defense and detection engineering.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://filedn.com/lY24cv0Ifefb… | 2024-11-13 | 2025-02-12 |
| DOMAIN | filedn.com | 2024-11-13 | 2025-02-12 |
| IPv4 | 104.168.165.203 | 2024-07-15 | 2025-02-12 |
| IPv4 | 104.168.157.45 | 2024-07-15 | 2025-02-12 |
| HASH | 9111d458d5665b1bf463859792e950f… | 2024-11-13 | 2024-11-14 |
| HASH | e87177e07ab9651b48664c3d2233424… | 2024-11-13 | 2024-11-14 |
| HASH | 7464850d7d6891418c503d0e1732812… | 2024-11-13 | 2024-11-14 |
| HASH | 022344029b8bf951ba02b11025fe26c… | 2024-11-13 | 2024-11-14 |
| HASH | 176e8a5a7b6737f8d3464c18a77deef… | 2024-11-13 | 2024-11-14 |
| HASH | f3e6e8df132155daf1d428dff61f0ca… | 2024-11-13 | 2024-11-14 |
| HASH | 48ee5d0d44a015876d867fa515b04c1… | 2024-11-13 | 2024-11-14 |
| HASH | 4bce97eff4430708299a1bb4142b9d3… | 2024-11-13 | 2024-11-14 |
| HASH | 878e3701df9b0abdaa7094e22d067c8… | 2024-11-13 | 2024-11-14 |
| HASH | a4cab67569d0b35c249dc536fb25dab… | 2024-11-13 | 2024-11-14 |
| YARA | rustyattr | 2024-11-13 | 2024-11-13 |
| URL | https://support.docsend.site/51… | 2024-11-13 | 2024-11-13 |
| URL | https://support.cloudstore.busi… | 2024-11-13 | 2024-11-13 |
| URL | https://filedn.com/lY24cv0Ifefb… | 2024-11-13 | 2024-11-13 |
| DOMAIN | support.cloudstore.business | 2024-11-13 | 2024-11-13 |
| DOMAIN | support.docsend.site | 2024-11-13 | 2024-11-13 |