RustDoor, also tracked as ThiefBucket, is a Rust-written macOS backdoor associated with North Korean cryptocurrency-focused operations, including activity attributed to BlueNoroff, Alluring Pisces, and Sapphire Sleet. It has targeted cryptocurrency-sector personnel and job-seeking software developers through recruiter impersonation and malicious interview or development projects, including booby-trapped Visual Studio projects. RustDoor masquerades as legitimate software updates or applications, establishes remote access, and can retrieve and execute additional payloads, including reverse-shell scripts. Observed variants hide artifacts on disk, collect and archive data associated with the LastPass browser extension, and exfiltrate collected archives to attacker-controlled infrastructure. RustDoor activity is also linked by infrastructure and tradecraft to RustBucket and Koi Stealer campaigns targeting macOS users in the cryptocurrency ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA and Microsoft confirmed on Tuesday that CVE-2026-68820 is being exploited... The vulnerability impacts Winsock... Check Point researchers explained that the malware first gathers information about the infected device before deploying an exploit for CVE-2026-68820.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Infrastructure overlap with ToneShell backdoor, Rustdoor and Koi stealer
“In this campaign, we discovered a Rust-based macOS malware nicknamed RustDoor masquerading as a legitimate software update…”
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The analysis of the script revealed an interesting and uncommon technique, namely to combine Python with Apple Scripting, as the filegrabber() function executes a large block of Apple script using the osascript -e command.
For two IPs of the ShadowSyndicate infrastructure, we found Cobalt strike beacons at the same timeframe that were linked to the Citrix bleed exploit attack campaign where Lockbit ransomware was chiefly deployed by affiliates.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a DPRK-attributed macOS malware whose crypto-wallet targeting list closely matches PHANTOMPULSE reconnaissance.
Mentioned only as a comparison for PHANTOMPULSE's crypto-wallet targeting list.
Rust-written macOS backdoor delivered via trojanized apps; described as linked to ransomware groups and designed to simplify cross-platform development.
Backdoor malware discussed through infrastructure and API-pattern overlap with ToneShell and Atomic/AMOS-related activity, especially in macOS-focused campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.