logo

Stealthy Attributes of Lazarus APT Group: Evading Detection with Extended Attributes

ID: 8f8d7f64-4dd8-51b6-a193-828ccaf69e4f

STIX ID: report--8f8d7f64-4dd8-51b6-a193-828ccaf69e4f

Feed Name: Group-IB Blog

Threat Score
60/100

Date Published: 2024-11-13

Date Updated: 2026-04-28

...
...

Group-IB researchers describe a macOS trojan family (RustyAttr) used by or linked to APT Lazarus that smuggles and executes shell scripts stored in custom extended file attributes via Tauri-built applications; the report details execution flow, decoys, interface commands, MITRE mappings, IOCs (domains, IPs, SHA256 hashes), and mitigations, noting limited samples, no confirmed victims, and that macOS Gatekeeper and a revoked signing certificate currently limit impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.