Stealthy Attributes of APT Lazarus: Evading Detection with Extended Attributes

2024-11-13 Group-IB

https://www.group-ib.com/blog/stealthy-attributes-of-apt-lazarus/

Thumbnail for Stealthy Attributes of APT Lazarus: Evading Detection with Extended Attributes

Group-IB identified a macOS technique attributed with moderate confidence to Lazarus in which malicious code is hidden inside custom extended attributes rather than in visible application files. The RustyAttr trojans were built with Tauri, used JavaScript-to-Rust calls to read an extended attribute named "test," and executed the embedded shell script while showing either a decoy PDF or a fake unsupported-version dialog. The scripts attempted to fetch follow-on content from staging servers such as support.cloudstore[.]business and support.docsend[.]site, and the infrastructure and hosting context overlapped with earlier Lazarus activity including RustBucket-related files. The samples were signed with a leaked certificate later revoked by Apple, were unnotarized, and were undetected on VirusTotal at analysis time, making the extended-attribute smuggling technique notable for macOS defense and detection engineering.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://filedn.com/lY24cv0Ifefb… 2024-11-13 2025-02-12
DOMAIN filedn.com 2024-11-13 2025-02-12
IPv4 104.168.165.203 2024-07-15 2025-02-12
IPv4 104.168.157.45 2024-07-15 2025-02-12
HASH 9111d458d5665b1bf463859792e950f… 2024-11-13 2024-11-14
HASH e87177e07ab9651b48664c3d2233424… 2024-11-13 2024-11-14
HASH 7464850d7d6891418c503d0e1732812… 2024-11-13 2024-11-14
HASH 022344029b8bf951ba02b11025fe26c… 2024-11-13 2024-11-14
HASH 176e8a5a7b6737f8d3464c18a77deef… 2024-11-13 2024-11-14
HASH f3e6e8df132155daf1d428dff61f0ca… 2024-11-13 2024-11-14
HASH 48ee5d0d44a015876d867fa515b04c1… 2024-11-13 2024-11-14
HASH 4bce97eff4430708299a1bb4142b9d3… 2024-11-13 2024-11-14
HASH 878e3701df9b0abdaa7094e22d067c8… 2024-11-13 2024-11-14
HASH a4cab67569d0b35c249dc536fb25dab… 2024-11-13 2024-11-14
YARA rustyattr 2024-11-13 2024-11-13
URL https://support.docsend.site/51… 2024-11-13 2024-11-13
URL https://support.cloudstore.busi… 2024-11-13 2024-11-13
URL https://filedn.com/lY24cv0Ifefb… 2024-11-13 2024-11-13
DOMAIN support.cloudstore.business 2024-11-13 2024-11-13
DOMAIN support.docsend.site 2024-11-13 2024-11-13

Related Actors

Related Reports

« Back