The DPRK strikes using a new variant of RUSTBUCKET
ID: 14f4d78e-e72c-5698-b6c6-d0194b9178f5
STIX ID: report--14f4d78e-e72c-5698-b6c6-d0194b9178f5
Feed Name: Elastic Security Labs
Threat Score
Elastic Security Labs reports a newly observed, undetected variant of the RUSTBUCKET macOS malware used by REF9135 (attributed to Lazarus/BlueNorOff) against a venture-backed cryptocurrency payment provider; the report details a three-stage infection flow, a new LaunchAgent persistence mechanism, dynamic C2 infrastructure and IoCs, defense-evasion techniques (including strict User-Agent checks), and provides detection and prevention guidance (Elastic Defend rules and YARA).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
