Researchers attributed the RustBucket malware campaign to Bluenoroff, a North Korea-linked intrusion set tied to financially motivated operations, and reported that the group expanded the malware to target macOS alongside a Windows .NET variant. The infection chain used a fake PDF reader and a specially crafted PDF document to trigger malicious behavior, collect host information, and retrieve additional payloads from command-and-control infrastructure via HTTP POST requests.
The campaign was linked to broader SnatchCrypto activity targeting cryptocurrency, fintech, venture capital, and other finance-related organizations across Asia, the United States, Europe, and the UAE. Investigators also connected the operation to phishing lures, typosquatting domains, and multiple delivery formats including LNK, MSI, OneNote, VHD, CAB, and CHM files, while the Windows variant was observed checking for antivirus products and using alternate execution paths such as rundll32 or explorer.exe injection to load later stages.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
In April 2023, Jamf published a report on RustBucket as a newly observed macOS malware family and linked the activity to Bluenoroff.
In March 2023, Sekoia.io observed MSI and OneNote files containing commands similar to previously reported VHD-based Bluenoroff activity, used to drop downloader sample 529c65521e8a07c8810b6d225f7e2a89.
Since at least December 2022, Bluenoroff has leveraged RustBucket, a malware family written in Rust and Objective-C, to target macOS systems. Sekoia.io assessed this as the first observed case of Bluenoroff targeting macOS users.
Since 2017, Bluenoroff has conducted financially motivated campaigns targeting cryptocurrency exchanges and venture capital-related entities in Europe, Asia, the United States, and the UAE. Sekoia.io assessed the newly observed activity as part of this broader SnatchCrypto campaign.
Bluenoroff, a North Korea-nexus intrusion set allegedly subordinated to RGB Bureau 121, has been tasked with revenue generation since at least 2015.
Researchers analyzed a new BlueNoroff-linked macOS loader variant, 'EdoneViewer,' delivered in a ZIP archive with a decoy PDF and using a valid Apple developer signature that was later revoked. The malware decrypted an AppleScript that fetched a second-stage Trojan from on-global[.]xyz, expanding known RustBucket-related tradecraft against crypto-focused targets.
Sekoia.io further investigated RustBucket infrastructure and attributed the activity to Bluenoroff with high confidence. The report also identified a Windows .NET variant and broader infrastructure tied to phishing lures, typosquatting domains, and multiple delivery formats.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 76 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.