Wednesday, 14 May 2025
  • My Feed
  • My Interests
  • My Saves
  • History
  • Blog
Subscribe
Capernaum
  • Finance
    • Cryptocurrency
    • Stock Market
    • Real Estate
  • Lifestyle
    • Travel
    • Fashion
    • Cook
  • Technology
    • AI
    • Data Science
    • Machine Learning
  • Health
    HealthShow More
    Foods That Disrupt Our Microbiome
    Foods That Disrupt Our Microbiome

    Eating a diet filled with animal products can disrupt our microbiome faster…

    By capernaum
    Skincare as You Age Infographic
    Skincare as You Age Infographic

    When I dove into the scientific research for my book How Not…

    By capernaum
    Treating Fatty Liver Disease with Diet 
    Treating Fatty Liver Disease with Diet 

    What are the three sources of liver fat in fatty liver disease,…

    By capernaum
    Bird Flu: Emergence, Dangers, and Preventive Measures

    In the United States in January 2025 alone, approximately 20 million commercially-raised…

    By capernaum
    Inhospitable Hospital Food 
    Inhospitable Hospital Food 

    What do hospitals have to say for themselves about serving meals that…

    By capernaum
  • Sport
  • 🔥
  • Cryptocurrency
  • Data Science
  • Travel
  • Real Estate
  • AI
  • Technology
  • Machine Learning
  • Stock Market
  • Finance
  • Fashion
Font ResizerAa
CapernaumCapernaum
  • My Saves
  • My Interests
  • My Feed
  • History
  • Travel
  • Health
  • Technology
Search
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
  • Categories
    • Technology
    • Travel
    • Health
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Home » Blog » Lazarus Group targets macOS with RustyAttr trojan malware
Data Science

Lazarus Group targets macOS with RustyAttr trojan malware

capernaum
Last updated: 2024-11-15 10:59
capernaum
Share
Lazarus Group targets macOS with RustyAttr trojan malware
SHARE

Lazarus Group targets macOS with RustyAttr trojan malware

Contents
What is RustyAttr trojan malware?Why is RustyAttr malware very risky?

The Lazarus Group targets macOS with a new trojan malware named RustyAttr, revealing an advanced method of hiding malicious code via extended attributes in files. Uncovered by the cybersecurity company Group-IB, RustyAttr represents a worrisome evolution in the tactics employed by this notorious North Korean state-backed hacking group.

What is RustyAttr trojan malware?

Researchers have linked RustyAttr’s deployment to the Lazarus Group since May 2024. This malware cleverly conceals its harmful scripts within extended attributes (EAs) of macOS files, which are hidden data containers that store additional information such as permissions and metadata. As these extended attributes are typically invisible in common user interfaces like Finder or Terminal, attackers can exploit them unobtrusively without arousing suspicion. The command-line utility `.xattr` provides attackers access to these hidden elements, allowing them to execute malicious scripts seamlessly.

In a somewhat nostalgic nod to techniques used in prior malware, like the 2020 Bundlore adware, RustyAttr uses a similar approach by embedding its payload in the extended attributes. This underscores the ongoing evolution of malware tactics, adapting to maintain effectiveness against evolving cybersecurity measures.

Lazarus Group targets macOS with RustyAttr trojan malware
Researchers have linked RustyAttr’s deployment to the Lazarus Group since May 2024 (Image credit)

The attack scenario crafted by Lazarus shows a cleverly designed application, built with the Tauri framework, that masquerades as a benign PDF file. This application, often containing job opportunity or cryptocurrency-related content—hallmarks of Lazarus’s previous campaigns—serves as bait. Upon execution, it either fetches and displays a decoy PDF about game project funding or mistakenly claims that the application does not support the version in use. This tactic cleverly distracts users while executing hidden shell scripts that trigger the malicious components.

Interestingly, the mechanism underlying RustyAttr involves a JavaScript file named “preload.js” that interacts with these extended attributes. This script uses functionalities from the Tauri framework to retrieve and execute the hidden malware. According to Group-IB researchers, “If the attribute exists, no user interface will be shown, whereas if the attribute is absent, a fake webpage will be displayed.” This behavior makes detection by antivirus solutions particularly challenging, as the malicious components rest undetected within the file’s metadata.

The applications associated with RustyAttr were initially signed with a now-revoked certificate, which allowed for a brief period of evading Gatekeeper protections on macOS. Although there have been no confirmed victims identified thus far, the researchers suspect that the Lazarus Group could be testing this stealthy approach for broader future attacks. Importantly, this tactic is new and has yet to be documented in the prominent MITRE ATT&CK framework, raising concerns about the adaptability and increasing sophistication of the threat actors involved.

Lazarus Group targets macOS with RustyAttr trojan malware
The applications associated with RustyAttr were initially signed with a now-revoked certificate (Image credit)

To stay protected from this emerging threat, cybersecurity experts advise users to be vigilant about file sources and to treat unsolicited PDF files—regardless of how legitimate they may seem—with skepticism. Enabling macOS’s Gatekeeper feature is essential, as it prevents the execution of untrusted applications. Regular updates and adopting advanced threat detection strategies are further recommended to stay ahead of such sophisticated attacks.

Why is RustyAttr malware very risky?

The implications of RustyAttr becoming a prevalent threat extend beyond just the exploit itself; they highlight a worrying trend in how malware continues to evolve in complexity and stealth. In recent years, North Korean hackers have significantly ramped up their activities, often targeting remote positions in organizations across the globe with promises of lucrative opportunities. While the ultimate goal of RustyAttr remains unclear at this stage, the potential for serious damage is undeniably present. As this group continues to refine its techniques, the cybersecurity community must remain vigilant, continuously adapting defenses in response to such advanced persistent threats.

By employing tactics involving minimal user interaction and leveraging commonly accepted file types, attackers like the Lazarus Group can remain under the radar for longer periods, potentially compromising sensitive data or systems. Staying informed and aware of these developments is critical for individuals and organizations to prevent falling victim to future attacks stemming from this or similar tactics.


Featured image credit: Florian Olivo/Unsplash

Share This Article
Twitter Email Copy Link Print
Previous Article Anthropic introduces prompt improver for AI developers Anthropic introduces prompt improver for AI developers
Next Article Fitbit’s new sleep journal feature to offer personalized insights Fitbit’s new sleep journal feature to offer personalized insights
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Using RSS feeds, we aggregate news from trusted sources to ensure real-time updates on the latest events and trends. Stay ahead with timely, curated information designed to keep you informed and engaged.
TwitterFollow
TelegramFollow
LinkedInFollow
- Advertisement -
Ad imageAd image

You Might Also Like

Clean code vs. quick code: What matters most?
Data Science

Clean code vs. quick code: What matters most?

By capernaum
Will Cardano’s AI upgrade help continue its upward trend? 
Data Science

Will Cardano’s AI upgrade help continue its upward trend? 

By capernaum

Daily Habits of Top 1% Freelancers in Data Science

By capernaum

10 Free Artificial Intelligence Books For 2025

By capernaum
Capernaum
Facebook Twitter Youtube Rss Medium

Capernaum :  Your instant connection to breaking news & stories . Stay informed with real-time coverage across  AI ,Data Science , Finance, Fashion , Travel, Health. Your trusted source for 24/7 insights and updates.

© Capernaum 2024. All Rights Reserved.

CapernaumCapernaum
Welcome Back!

Sign in to your account

Lost your password?