• Book Dewayne Hart
  • Dewaynehart@dewaynehart.com
  • (470) 409 8316
  • Speaker Bio
  • Home
  • About
  • Speaker
  • Books
  • Podcast
  • Contact
  • Home
  • About
  • Speaker
  • Books
  • Podcast
  • Contact
Facebook-f Linkedin-in Youtube X-twitter Globe
Order books

New RustyAttr Malware Targets macOS Through Extended Attribute Abuse

Posted on November 15, 2024 by admin

[ad_1]

Nov 14, 2024Ravie LakshmananCryptojacking / Threat Intelligence

RustyAttr Malware

Threat actors have been found leveraging a new technique that abuses extended attributes for macOS files to smuggle a new malware called RustyAttr.

The Singaporean cybersecurity company has attributed the novel activity with moderate confidence to the infamous North Korea-linked Lazarus Group, citing infrastructure and tactical overlaps observed in connection with prior campaigns, including RustBucket.

Extended attributes refer to additional metadata associated with files and directories that can be extracted using a dedicated command called xattr. They are often used to store information that goes beyond the standard attributes, such as file size, timestamps, and permissions.

Cybersecurity

The malicious applications discovered by Group-IB are built using Tauri, a cross-platform desktop application framework, and signed with a leaked certificate that has since been revoked by Apple. They include an extended attribute that’s configured to fetch and run a shell script.

The execution of the shell script also triggers a decoy, which serves as a distraction mechanism by either displaying an error message “This app does not support this version” or a seemingly harmless PDF document related to the development and funding of gaming projects.

RustyAttr Malware

“Upon executing the application, the Tauri application attempts to render a HTML webpage using a WebView,” Group-IB security researcher Sharmine Low said. “The [threat actor] used some random template pulled off the internet.”

But what’s also notable is that these web pages are engineered to load a malicious JavaScript, which then obtains the content of the extended attributes and executes it by means of a Rust backend. That said, the fake web page is eventually displayed only in cases where there are no extended attributes.

The end goal of the campaign remains unclear, especially in light of the fact that there has been no evidence of any further payloads or confirmed victims.

Cybersecurity

“Fortunately, macOS systems provide some level of protection for the found samples,” Low said. “To trigger the attack, users must disable Gatekeeper by overriding malware protection. It is likely that some degree of interaction and social engineering will be necessary to convince victims to take these steps.”

The development comes as North Korean threat actors have been engaging in extensive campaigns that aim to secure remote positions with businesses across the world, as well as trick current employees working at cryptocurrency companies into downloading malware under the pretext of coding interviews.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



[ad_2]

Recent Posts

  • No Blind Spots: A Veteran’s Blueprint to Protect Critical Infrastructure
  • Cybersecurity as a Growth Lever: A Board-Ready Playbook for CIOs and CTOs
  • From Reaction to Readiness: Building a Cybersecurity Mindset for Proactive Defense
  • Cybersecurity Leadership in 2026: Executive Decisions that Drive Resilience and Growth
  • Implementing a Hacker’s Mindset: Build a Security Culture That Hunts, Learns, and Wins

Recent Comments

No comments to show.

Archives

  • March 2026
  • February 2026
  • July 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023

Categories

  • Cyber News
  • Uncategorized

Book Dewayne Hart for your next event

  • Dewaynehart@dewaynehart.com
  • (470) 409 8316
Facebook-f Linkedin-in Youtube X-twitter Globe
© 2025 Dewayne Hart | Cybersecurity Leadership & Innovation