HomeSecurityBlueNoroff group targets Apple devices with new RustBucket macOS malware

BlueNoroff group targets Apple devices with new RustBucket macOS malware

North Korean threat actor BlueNoroff, known for its financial motives, is suspected of being behind a new strain of Apple macOS malware called RustBucket.

BlueNoroff group targets Apple devices with new RustBucket macOS malware
BlueNoroff group targets Apple devices with new RustBucket macOS malware

Apple's device management company attributed it to a threat actor known as BlueNoroff, a subgroup of the infamous Lazarus cluster, which is also tracked under the aliases APT28, Nickel Gladstone, Sapphire Sleet, Stardust Chollima, and TA444.

The connections emerge from tactics and infrastructure that overlap with a previous campaign uncovered by Russian cybersecurity firm Kaspersky in late December 2022, which likely targeted Japanese financial entities using fake domains impersonating venture capital firms.

BlueNoroff, unlike the other entities that make up the Lazarus group, is known for sophisticated cyber heists targeting the SWIFT system, as well as crypto exchanges, as part of a set of attacks tracked as CryptoCore.

Earlier this year, the US Federal Bureau of Investigation (FBI) implicated the threat actor in the theft of $100 million in cryptocurrency assets from Harmony Horizon Bridge in June 2020.

BlueNoroff's attack repertoire is also said to have undergone a significant change in recent months, with the group using work-themed bait to trick email recipients into entering their credentials on fake landing pages.

BlueNoroff group targets Apple devices with new RustBucket macOS malware

The macOS malware detected by Jamf masquerades as an “Internal PDF Viewer” application to trigger the infection. It is worth noting, however, that the success of the attack relies on the victim manually bypassing Gatekeeper protections.

In fact, it is an AppleScript file designed to retrieve a second-stage payload from a remote server, which also bears the same name as its predecessor. Both malicious applications are signed with an ad-hoc signature.

The second-stage payload, written in Objective-C, is a basic application that offers the ability to view PDF files and initiates the next phase of the attack chain only when a compromised PDF file is opened using the application.

One such nine-page PDF document, spotted by Jamf, claims to offer an “investment strategy,” which, when launched, communicates with a command and control (C2) server to download and execute a third-stage trojan, a Mach-O executable written in Rust, which has capabilities to execute system-recognition commands.

BlueNoroff

It is currently unclear how the initial access was gained and whether the attacks were successful, but this development is a sign that threat actors are adapting their toolkits to tailor malware using programming languages ​​such as Go and Rust.

The findings also come after a busy period of attacks orchestrated by the Lazarus group, targeting organizations in various countries and industry verticals to gather strategic intelligence and carry out cryptocurrency theft.

The Lazarus Group (also known as Hidden Cobra and Diamond Sleet) is not so much a separate organization as an umbrella term for a mix of state-sponsored and criminal hacking groups that are part of the Reconnaissance General Bureau (RGB), North Korea's main external intelligence apparatus.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS