RustBucket is a multi-stage macOS malware family attributed with high confidence to BlueNoroff, a North Korean threat actor associated with the Lazarus ecosystem. It emerged in 2023 as part of a broader shift by BlueNoroff toward sustained targeting of macOS users, particularly in cryptocurrency and Web3-related operations. The malware is best characterized as a Rust-based backdoor delivered through social-engineering lures that masquerade as PDF viewer applications and related document-themed software.
The infection chain typically begins with a malicious AppleScript applet or Swift-based application bundle presented as a PDF reader or protected document viewer. Victims are enticed to open a lure document, after which the first-stage component retrieves and launches additional stages. Intermediate loaders have been observed in Swift and Objective-C variants and are capable of downloading the final Rust payload. Some campaigns used fake PDF applications that bypassed or weakened user trust controls through valid signing and notarization prior to certificate revocation.
The final-stage RustBucket payload is a macOS backdoor that performs host profiling, communicates with command-and-control infrastructure, and supports follow-on payload delivery. Reported functionality includes collecting basic system and disk information, downloading and executing additional malware, and processing attacker commands. Multiple variants show active development, including changes in implementation language across stages, support for both Intel and Apple silicon systems, and evolution in persistence mechanisms.
Later RustBucket variants introduced persistence through LaunchAgents and by copying the backdoor to a disguised location within the user profile. Related reporting also links internal component naming such as webT or macWebT to later DPRK-attributed tooling overlaps. RustBucket has been associated with campaigns targeting macOS users in cryptocurrency, finance, and blockchain-adjacent contexts, and researchers have noted operational and tooling relationships with other BlueNoroff-linked macOS activity including KandyKorn and subsequent campaigns that reused infrastructure, code patterns, or tradecraft.
RustBucket is significant as an example of a state-linked macOS intrusion set combining social engineering, staged loaders, Gatekeeper evasion, persistence, and modular post-compromise capability in support of financially motivated espionage and theft operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Внутреннее имя проекта macOS RAT - macWebT - связывается с модулем webT из кампании RustBucket, атрибутированной BlueNoroff (подгруппа Lazarus).
Внутреннее имя проекта macOS RAT - macWebT - связывается с модулем webT из кампании RustBucket, атрибутированной BlueNoroff (подгруппа Lazarus).
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious PDF dropped a second-stage malware known as RUSTBUCKET... and in this instance persisted, via a Launch Agent disguised as “Safari Update”.
The malicious PDF dropped a second-stage malware known as RUSTBUCKET... and in this instance persisted, via a Launch Agent disguised as “Safari Update”.
The Stage 2 payload requires a specially-crafted PDF to unlock the code which would lead to the downloading of the Stage 3 and provide an XOR’d key to decode the obfuscated C2 appended to the end of the PDF.
It ad-hoc code-signs dropped payloads ( codesign --force --deep --sign - ) to bypass Gatekeeper.
The DoPost function is used to make the HTTP Post request to the C2 using libcurl.
88 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Lazarus/BlueNoroff-linked campaign whose webT module resembles the macOS RAT naming seen in the axios incident.
macOS malware cited as using LaunchAgents/LaunchDaemons persistence mechanisms.
Referenced as part of attribution context linking the campaign to DPRK activity via the webT module; no direct operational role in this axios compromise is described beyond that linkage.
Backdoor trojan (noted in 2023) that bypasses Gatekeeper via a fake PDF app and enables follow-on malware installation and espionage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.