Stealthy Attributes of Lazarus APT Group: Evading Detection with Extended Attributes
ID: 8f8d7f64-4dd8-51b6-a193-828ccaf69e4f
STIX ID: report--8f8d7f64-4dd8-51b6-a193-828ccaf69e4f
Feed Name: Group-IB Blog
Threat Score
Group-IB researchers describe a macOS trojan family (RustyAttr) used by or linked to APT Lazarus that smuggles and executes shell scripts stored in custom extended file attributes via Tauri-built applications; the report details execution flow, decoys, interface commands, MITRE mappings, IOCs (domains, IPs, SHA256 hashes), and mitigations, noting limited samples, no confirmed victims, and that macOS Gatekeeper and a revoked signing certificate currently limit impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
