macOS users have been targeted by attacks using a new backdoor , codenamed RustDoor , which is said to have been operating in secret since November 2023.

Bitdefender researchers have dubbed the new backdoor RustDoor. The malware impersonates an update for Microsoft Visual Studio and targets Intel and Arm architectures.
We don't know for sure the original way were compromised to distribute the RustDoor backdoor, but it is said to use FAT binaries containing Mach-O files.
See also: Pirated apps infect macOS systems with malware
Researchers have identified several variants of the malware with minor modifications. The oldest RustDoor sample is dated November 2, 2023. The new versions obviously show that the backdoor continues to evolve.
It has many capabilities that allow it to collect and upload files, as well as gather information about the compromised endpoint.
Some versions of RustDoor also include configurations with details about what data to collect, which extensions and directories to target, and which to exclude.
See also: Pirated macOS apps drain users' wallets
The stolen information is sent to the command-and-control (C2) server controlled by the backdoor operators.
Bitdefender researchers believe the malware may be linked to ransomware such as Black Basta and BlackCat. The speculation stems from some overlap in the C2 infrastructure.

Protect macOS from malware
The first step in protecting your macOS from malware is to install reliable antivirus software. This will monitor your system for any suspicious activity and remove any attacks before they can cause damage.
Second, regularly update your operating system and all applications your. Updates often include security patches that can protect your computer from the latest threats, including RustDoor.
See also: MacOS info-stealer malware evades detection by XProtect
Additionally, use settings security macOS's. This includes turning on the firewall and adjusting security and privacy preferences to limit access to your data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, avoid installing software from untrusted sources. Software that doesn't come from the App Store or verified developers may contain hidden malware (like RustDoor). Also, avoid opening links and files found in emails that look strange or you're not expecting.
Source: thehackernews.com
