logo

RustDoor macOS Backdoor Targets Cryptocurrency Firms with Fake Job Offers

ID: 9db842b9-811f-5c66-a957-f20f030a5ec5

STIX ID: report--9db842b9-811f-5c66-a957-f20f030a5ec5

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-02-16

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Security vendors discovered an ongoing targeted campaign against cryptocurrency companies using a macOS backdoor named RustDoor. The implant — written in Rust and accompanied by Golang-based binaries — is distributed via malicious ZIP archives and fake Visual Studio updates that execute shell scripts, fetch the payload from a website (turkishfurniture.blog), and display a decoy PDF. Researchers identified actor-controlled domains (e.g., sarkerrentacars.com), a leaky C2 endpoint exposing infected hosts, and at least three victim companies (two in Hong Kong and one in Lagos), with potential ties to criminal malware-as-a-service activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.