New Rust-Based macOS Backdoor Steals Files, Linked to Ransomware Groups
ID: 7bb74a9e-71a2-5f67-9a07-dcfda0bd2316
STIX ID: report--7bb74a9e-71a2-5f67-9a07-dcfda0bd2316
Feed Name: HackRead
Threat Score
**Trojan.MAC.RustDoor** is a Rust-based macOS backdoor active since November 2023 that impersonates Visual Studio updates to deploy FAT binaries for x86_64 and ARM, supports remote commands (ps, shell, upload, download, etc.), exfiltrates specific user documents and notes, uses multiple persistence mechanisms (LaunchAgents, cron, Dock, zshrc), and communicates with C2 endpoints; artefacts and IoCs indicate a possible link to BlackBasta/ALPHV ransomware operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
