RustDoor macOS Backdoor Targets Cryptocurrency Firms with Fake Job Offers
ID: 9db842b9-811f-5c66-a957-f20f030a5ec5
STIX ID: report--9db842b9-811f-5c66-a957-f20f030a5ec5
Feed Name: The Hacker News
Security vendors discovered an ongoing targeted campaign against cryptocurrency companies using a macOS backdoor named RustDoor. The implant — written in Rust and accompanied by Golang-based binaries — is distributed via malicious ZIP archives and fake Visual Studio updates that execute shell scripts, fetch the payload from a website (turkishfurniture.blog), and display a decoy PDF. Researchers identified actor-controlled domains (e.g., sarkerrentacars.com), a leaky C2 endpoint exposing infected hosts, and at least three victim companies (two in Hong Kong and one in Lagos), with potential ties to criminal malware-as-a-service activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
