Elastic Security Labs identified a new macOS variant of RUSTBUCKET in the REF9135 campaign targeting a U.S.-headquartered cryptocurrency payment-services provider. Elastic attributed the activity with high confidence to DPRK-linked Lazarus Group/BlueNorOff operations, citing overlaps in malware, victimology, and command-and-control infrastructure.
The malware uses Swift and Rust stages, supports both Intel and ARM-based Macs, and establishes persistence through a macOS LaunchAgent. The operators used restrictive, nonstandard User-Agent validation to limit payload delivery and rapidly rotated command-and-control infrastructure to frustrate analysis and detection; no VirusTotal engines detected the variant when Elastic reported it.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Elastic analyzed a Swift- and Rust-based RUSTBUCKET variant that established LaunchAgent persistence, supported Intel and ARM macOS systems, collected host information, and could receive commands to execute uploaded Mach-O binaries or shell scripts. The sample had no VirusTotal antivirus detections at the time of Elastic's research.
After researchers collected Stage 2 and Stage 3 payloads, the operators replaced the C2 domain crypto.hondchain[.]com with starbucls[.]xyz. The campaign used strict custom User-Agent checks and returned HTTP 405 errors for requests lacking the required values.
The REF9135 campaign targeted a U.S.-headquartered cryptocurrency payment-services provider with a new macOS RUSTBUCKET variant. Elastic assessed with high confidence that the activity was linked to the DPRK-operated Lazarus Group and its financially motivated BlueNorOff sub-unit.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.