logo

RustDoor and Koi Stealer for macOS Used by North Korea-Linked Threat Actor to Target the Cryptocurrency Sector

ID: 4dd5575b-3c52-5b45-a491-3b8b8a7daf87

STIX ID: report--4dd5575b-3c52-5b45-a491-3b8b8a7daf87

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2025-02-26

Date Updated: 2026-04-28

Author: Adva Gabay and Daniel Frank

...
...

This Unit 42 report analyzes a targeted macOS campaign that lured crypto-sector software developers with fake Visual Studio projects and updates to deploy RustDoor backdoors and a new macOS Koi Stealer infostealer variant; it documents execution stages, data-stealing capabilities (notably cryptocurrency wallets and credentials), TTPs (AppleScript use, privilege prompts, reverse shell attempts), IoCs (file hashes, domains, IPs, encryption key), and links the activity with moderate confidence to North Korean-affiliated actors while providing detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.