Several companies active in the cryptocurrency sector are the target of a new Apple called RustDoor.

RustDoor was first documented by Bitdefender last week, describing it as malware capable of harvesting and uploading files, as well as gathering information about infected machines. It is distributed by disguising itself as a Visual Studio update.
Read more: RustDoor: New backdoor targets macOS systems
Despite previous evidence revealing at least three different variants of the backdoor, the exact initial propagation mechanism remained unknown.
Following this report, the Romanian cybersecurity told The Hacker News that the malware was used as part of a targeted attack, rather than as part of an entire campaign. Additionally, it was noted that additional techniques were found that were responsible for downloading and executing RustDoor.
“Some of these first-stage programs claim to be PDF files with job opportunities, but in reality they are malware that downloads and executes scripts. In addition, they download and open an innocent PDF file containing a confidentiality agreement,” said Bogdan Botezatu, director of threat research and reporting at Bitdefender.
Since then, three more malicious samples have been discovered that act as first stages of attack payloads. Each of these ZIP files is considered a job offer, while the previous RustDoor binaries predate it by almost a month.
The new element of the attack chain – namely the archive files (“Jobinfo.app.zip” or “Jobinfo.zip”) – includes a basic shell script that takes care of extracting information from the Turkishfurniture[.]blog website. Furthermore, it is designed to display the harmless seduction PDF file (“job.pdf”) hosted on the same website as a way to gain attention.
Bitdefender reported that four new Golang-based binaries were detected that communicate with a domain controlled by hackers (“sarkerrentacars[.]com”). The purpose of these files is to collect information about the victim’s computer and its network connections, using the system_profiler and networksetup tools that are part of the macOS operating system.
See also: Russian Turla hackers target NGOs with new TinyTurla-NG backdoor
Additionally, binaries can provide detailed information via the “diskutil list” command. Additionally, they can retrieve a wide range of kernel parameters and configuration values using the “sysctl -a” command.
With a closer analysis of the command and control (C2) structure, we also discovered a leak in the endpoint (“/client/bots”) that allows the collection of details about current victims, including the times the infected host was logged in and the last activity recorded.
The developments are many, as South Korea’s National Intelligence Service (NIS) has revealed that an IT organization, linked to Office No. 39 of the North Korean Workers’ Party, is generating illegal revenue by selling thousands of gambling websites. These websites contain malware that is used by other cybercriminals to steal sensitive data from unsuspecting gamblers.

The company behind the malware-as-a-service (MaaS) program is Gyeongheung (also known as Gyonghung), a 15-person team based in Dandong. It allegedly received $5,000 from an unknown criminal organization in South Korea in exchange for creating a single website, as well as $3,000 per month for the site's maintenance, according to Yonhap.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Read more: DSLog backdoor installed via SSRF vulnerability in Ivanti
Source: thehackernews.com
