logo

New RustDoor macOS malware impersonates Visual Studio update

ID: 09492502-5dbb-5a00-9451-e2b82d27b6ec

STIX ID: report--09492502-5dbb-5a00-9451-e2b82d27b6ec

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-02-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

RustDoor is a Rust-written macOS backdoor delivered since at least November 2023 via fake Visual Studio for Mac updater binaries (FAT Mach-O supporting Intel and Apple Silicon). Researchers (Bitdefender) observed multiple variants with persistence mechanisms (Cron, LaunchAgents, ~/.zshrc edits), remote command capabilities (shell, upload/download, process management, exfiltration), and communication with four C2 servers; IoCs and some C2 infrastructure overlap suggest a possible, but not confirmed, relation to ALPHV/BlackCat ransomware affiliates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.