logo

North Korean Hackers Deploy RustDoor and Koi Stealer to Target Cryptocurrency Developers on macOS

ID: 59445286-98e7-5538-ae7c-da3bd3a95e83

STIX ID: report--59445286-98e7-5538-ae7c-da3bd3a95e83

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2025-02-28

Date Updated: 2026-04-22

Author: do son

...
...

Unit 42 describes a macOS-focused campaign named CL-STA-240 ("Contagious Interview") that lures developers with fake job interviews and installs RustDoor and a macOS Koi Stealer variant to gain persistence, exfiltrate cryptocurrency wallets and credentials (including LastPass/Keychain data), and communicate with attacker C2 (notably IP 31.41.244.92); researchers link the TTPs with DPRK-associated groups such as BlueNoroff/Lazarus.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.