RustBucket is a multi-stage backdoor family targeting macOS and attributed with high confidence to BlueNoroff, a financially motivated DPRK-linked Lazarus Group subcluster. Active since at least December 2022, it has primarily targeted cryptocurrency, fintech, venture-capital, and other finance-related organizations and personnel. Campaigns commonly use social engineering lures involving purported confidential, investment, or job-related PDF documents and a functional but trojanized PDF-viewer application. The initial application may display a benign decoy document while retrieving subsequent malware stages.
RustBucket loaders have been implemented in AppleScript, Swift, and Objective-C, while later backdoor components are Rust-based Mach-O binaries supporting Intel and Apple Silicon systems. The backdoor profiles the host, including system attributes, running processes, installation and boot information, and disk details, then transmits collected information to command-and-control infrastructure. It accepts operator commands to terminate, retrieve, and execute additional Mach-O binaries or shell scripts, making it a foothold for follow-on compromise.
Later macOS variants added user-level LaunchAgent persistence and used masquerading intended to resemble legitimate system-update activity. RustBucket variants have also employed specially crafted PDFs to gate execution, encoded configuration, strict HTTP request validation, infrastructure rotation, and environmental checks associated with analysis or virtualized systems. A related Windows .NET implementation uses a similar fake PDF-reader workflow, performs host and network discovery, checks for security products, and can use alternate execution paths including process injection. RustBucket tooling and infrastructure have shown overlap with other BlueNoroff-associated macOS activity, including KandyKorn-related delivery chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The new RUSTBUCKET variant targets macOS, adds built-in LaunchAgent persistence, gathers system information, communicates with C2 infrastructure, and can receive commands to terminate or download and execute Mach-O binaries or shell scripts.
The new RUSTBUCKET variant targets macOS, adds built-in LaunchAgent persistence, gathers system information, communicates with C2 infrastructure, and can receive commands to terminate or download and execute Mach-O binaries or shell scripts.
The new RUSTBUCKET variant targets macOS, adds built-in LaunchAgent persistence, gathers system information, communicates with C2 infrastructure, and can receive commands to terminate or download and execute Mach-O binaries or shell scripts.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Bluenoroff’s observed initial intrusion vector includes phishing emails, as well as leveraging social networks such as LinkedIn.
Bluenoroff’s observed initial intrusion vector includes phishing emails, as well as leveraging social networks such as LinkedIn.
During Stage 1, the process begins with the execution of an AppleScript utilizing the /usr/bin/osascript command.
Command ID 0x30 enables the operator to upload malicious Mach-O binaries or shell scripts to the system and execute them.
Launching the LNK file results in downloading a Javascript file from Bluenoroff-controlled C2 server and executing it using mshta.exe... The downloaded file is an obfuscated Javascript.
The malicious PDF dropped a second-stage malware known as RUSTBUCKET... and in this instance persisted, via a Launch Agent disguised as “Safari Update”.
It establishes its own persistence by adding a plist file at /Users/<user>/Library/LaunchAgents/com.apple.systemupdate.plist.
If there is no antivirus, the DLL perform code injection on the provided explorer.exe process.
The malicious PDF dropped a second-stage malware known as RUSTBUCKET... and in this instance persisted, via a Launch Agent disguised as “Safari Update”.
It establishes its own persistence by adding a plist file at /Users/<user>/Library/LaunchAgents/com.apple.systemupdate.plist.
The downloaded file is an obfuscated Javascript: 5ca7c871dfe24b27b5cf7e9bf087f44c7620d78a1d4fa76373f22abedbdf8f82 The obfuscation method is straightforward and consists in encoding some characters in UTF-8 and Hex.
The LaunchAgent is named com.apple.systemupdate and executes the file located at /Users/<user>/Library/Metadata/System Update.
If there is no antivirus, the DLL perform code injection on the provided explorer.exe process.
The fake PDF reader uses a hardcoded 100-bytes XOR key to decrypt the new content of the document and the C2 server configuration... This script decodes its base64 block, writes it in a file 'tyrbz.js' and runs it.
It ad-hoc code-signs dropped payloads ( codesign --force --deep --sign - ) to bypass Gatekeeper.
Launching the LNK file results in downloading a Javascript file from Bluenoroff-controlled C2 server and executing it using mshta.exe.
If one of this antivirus is found, the DLL call the OpenProcess API to run the following command: rundll32.exe %s\DevExpress.Xpr.v19.2.dll,Update
This backdoor collects information about the compromised machine (name, active processes, network configuration, etc.) and sends this information to the C2 using POST requests.
The malware proceeds to gather comprehensive system information, including: List of active processes ... Status of all running processes within the system.
The malware proceeds to gather comprehensive system information, including: Computer name ... Current timestamp ... Installation timestamp ... System boot time.
177 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Lazarus/BlueNoroff-linked campaign whose webT module resembles the macOS RAT naming seen in the axios incident.
macOS malware cited as using LaunchAgents/LaunchDaemons persistence mechanisms.
Referenced as part of attribution context linking the campaign to DPRK activity via the webT module; no direct operational role in this axios compromise is described beyond that linkage.
RustBucket is a fake PDF reader malware family used by Bluenoroff that targets macOS and Windows. It installs a backdoored but functional PDF reader, requires a specific decoy PDF to trigger execution, decrypts embedded configuration including the C2, downloads a follow-on payload, and deploys a backdoor that profiles the host, sends system information to C2, receives commands, and can load additional stages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.