MacOS Targeted by New Backdoor Linked to ALPHV Ransomware
ID: 072fc353-ffa7-51e8-9965-63636921cb16
STIX ID: report--072fc353-ffa7-51e8-9965-63636921cb16
Feed Name: Dark Reading
Bitdefender researchers have identified Trojan.MAC.RustDoor, a Rust-written macOS backdoor that impersonates a Visual Studio Code update to collect files (Desktop, Documents, user notes), compress them into a ZIP, and exfiltrate them to C2 servers. Multiple variants have been active for at least three months; artifacts and three of four C2s overlap with prior ransomware campaigns, suggesting a possible operational link to the ALPHV/BlackCat ransomware group, though attribution remains unconfirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
