Summary: [/subscribe_to_unlock_form]
Summary: [emaillocker id="1283"]
Researchers has discovered a new variant of the RUSTBUCKET malware, previously associated with the BlueNoroff group. By examining the RUSTBUCKET code, the researchers have discovered new persistence capabilities, indicating active development of this malware family. Additionally, the variant remains undetected by existing antivirus engines, and its command-and-control infrastructure employs dynamic techniques to evade detection. The research investigation into REF9135 reveals that it employs the RUSTBUCKET malware for sustained operations targeting cryptocurrency payment services providers. The victim targeted by the REF9135 campaign is a venture-backed cryptocurrency company based in the European Union. The victim's profile aligns with previous reporting on BlueNorOff, which has a history of targeting organizations with significant cryptocurrency holdings for the purpose of theft.

Infection Chain
The malware execution begins with an AppleScript using the /usr/bin/osascript command, which downloads the Stage 2 binary from the command and control (C2) server using cURL. The Stage 2 binary is saved to /users/shared/.pd. The Stage 2 binary, written in Swift, expects a C2 URL as a parameter. It makes a POST request to the C2 server, gathering system information and receiving a command ID in response. The commands include self-termination or uploading and executing malicious binaries or shell scripts. The Stage 3 malware, a FAT binary supporting ARM and Intel architectures written in Rust, collects system information and communicates with the C2 server. The C2 server provides command instructions, including self-termination or uploading and executing malicious payloads. he updated RUSTBUCKET sample achieves persistence by adding a plist file in the LaunchAgents folder and copying the binary to a specific location. The plist file contains various key-value pairs defining the LaunchAgent's behavior and execution.
RUSTBUCKET has been associated with the BlueNorOff group, believed to operate on behalf of the DPRK. The malware's networking infrastructure includes various C2 domains associated with DangerousPassword, BlueNorOff, and the DPRK campaigns. Additional analysis reveals clustering of domains and IP addresses, indicating high confidence in associating them with the REF9135 campaign. The campaign shows rapid creation of new hosts to evade detection.
Threat Profile:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| T1053 | Scheduled Task/Job | |
| Defense Evasion | T1134 | Access Token Manipulation |
| Discovery | T1082 | System Information Discovery |
| Command and Control | T1105 | Ingress Tool Transfer |
| T1071 | Application Layer Protocol |
References:
The following reports contain further technical details:
https://thehackernews.com/2023/07/beware-new-rustbucket-malware-variant.html
[/emaillocker]