logo

New macOS Backdoor Written in Rust Shows Possible Link with Windows Ransomware Group

ID: 16434a57-d476-5354-91ec-0fcf0399470a

STIX ID: report--16434a57-d476-5354-91ec-0fcf0399470a

Feed Name: Bitdefender Labs

Threat Score
75/100

Date Published: 2024-02-08

Date Updated: 2026-04-27

Author: Andrei LAPUSNEANU

...
...

Bitdefender researchers describe an active macOS backdoor family dubbed Trojan.MAC.RustDoor written in Rust (with Go-based loaders observed) that has been distributed as fake app/binary installers since at least November 2023; the malware supports remote shell/file operations, collects system and user data (including targeted documents and Apple Notes), persists via cron/LaunchAgents/.zshrc/Dock modification, communicates with multiple C2 endpoints offering task management and exfiltration APIs, and includes numerous IOCs (file hashes, download domains, C2 URLs) with suspected victims in the cryptocurrency sector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.