New RustDoor macOS malware impersonates Visual Studio update
ID: 09492502-5dbb-5a00-9451-e2b82d27b6ec
STIX ID: report--09492502-5dbb-5a00-9451-e2b82d27b6ec
Feed Name: Bleeping Computer
RustDoor is a Rust-written macOS backdoor delivered since at least November 2023 via fake Visual Studio for Mac updater binaries (FAT Mach-O supporting Intel and Apple Silicon). Researchers (Bitdefender) observed multiple variants with persistence mechanisms (Cron, LaunchAgents, ~/.zshrc edits), remote command capabilities (shell, upload/download, process management, exfiltration), and communication with four C2 servers; IoCs and some C2 infrastructure overlap suggest a possible, but not confirmed, relation to ALPHV/BlackCat ransomware affiliates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
