RustDoor and Koi Stealer for macOS Used by North Korea-Linked Threat Actor to Target the Cryptocurrency Sector
ID: 4dd5575b-3c52-5b45-a491-3b8b8a7daf87
STIX ID: report--4dd5575b-3c52-5b45-a491-3b8b8a7daf87
Feed Name: Palo Alto Networks Unit 42
This Unit 42 report analyzes a targeted macOS campaign that lured crypto-sector software developers with fake Visual Studio projects and updates to deploy RustDoor backdoors and a new macOS Koi Stealer infostealer variant; it documents execution stages, data-stealing capabilities (notably cryptocurrency wallets and credentials), TTPs (AppleScript use, privilege prompts, reverse shell attempts), IoCs (file hashes, domains, IPs, encryption key), and links the activity with moderate confidence to North Korean-affiliated actors while providing detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
