logo

MacOS Targeted by New Backdoor Linked to ALPHV Ransomware

ID: 072fc353-ffa7-51e8-9965-63636921cb16

STIX ID: report--072fc353-ffa7-51e8-9965-63636921cb16

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-02-09

Date Updated: 2026-04-21

Author: Becky Bracken, Editor, Dark Reading

...
...

Bitdefender researchers have identified Trojan.MAC.RustDoor, a Rust-written macOS backdoor that impersonates a Visual Studio Code update to collect files (Desktop, Documents, user notes), compress them into a ZIP, and exfiltrate them to C2 servers. Multiple variants have been active for at least three months; artifacts and three of four C2s overlap with prior ransomware campaigns, suggesting a possible operational link to the ALPHV/BlackCat ransomware group, though attribution remains unconfirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.