logo

New Rust-Based macOS Backdoor Steals Files, Linked to Ransomware Groups

ID: 7bb74a9e-71a2-5f67-9a07-dcfda0bd2316

STIX ID: report--7bb74a9e-71a2-5f67-9a07-dcfda0bd2316

Feed Name: HackRead

Threat Score
70/100

Date Published: 2024-02-09

Date Updated: 2026-04-22

Author: Waqas

...
...

**Trojan.MAC.RustDoor** is a Rust-based macOS backdoor active since November 2023 that impersonates Visual Studio updates to deploy FAT binaries for x86_64 and ARM, supports remote commands (ps, shell, upload, download, etc.), exfiltrates specific user documents and notes, uses multiple persistence mechanisms (LaunchAgents, cron, Dock, zshrc), and communicates with C2 endpoints; artefacts and IoCs indicate a possible link to BlackBasta/ALPHV ransomware operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.