RustDoor Backdoor Targets macOS Systems

Researchers have discovered a new macOS backdoor coded in Rust, suggesting connections to the ransomware families Black Basta and Alphv/BlackCat. Named RustDoor, the malware pretends to be Visual Studio, supporting both Intel and Arm architectures, and has been in circulation since November 2023, successfully evading detection for approximately three months. Multiple variants of RustDoor have been identified, all sharing the same backdoor functionality with slight differences.

These analyzed samples of RustDoor exhibit the capability to execute various commands for file harvesting and exfiltration, as well as collecting information about the infected system. The gathered data is then transmitted to a command-and-control (C&C) server, generating a victim ID for subsequent communication.

Rust Dates Back to Late 2023

The initial variant, detected in November 2023, seemed to be a test version lacking a complete persistence mechanism and featuring a 'test' plist file. The second variant, observed at the end of November, had larger files, an intricate JSON configuration, and an Apple script designed for extracting specific documents from the Documents and Desktop folders, including user notes. This variant concealed the copied documents in a hidden folder, compressing them into a ZIP archive before sending them to the C&C server.

Researchers found that the RustDoor configuration file includes options for mimicking various applications, providing choices to customize a simulated administrator password dialog. Some configurations specify data to collect, such as maximum size and number of files, targeted extensions and directories, or directories to exclude.

The JSON configuration also references four persistence mechanisms: using cronjobs, employing LaunchAgents for execution at login, modifying a file for execution when a new ZSH session is opened, and adding the binary to the dock.

Additionally, a third variant has been identified, which researchers believe to be the original one, first observed on November 2. This variant is less complex, lacking the Apple script and embedded configuration found in later versions.

February 13, 2024
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.