Summary:
Researcher has identified new threat targeting Mac OS users: a previously undocumented backdoor written in Rust, boasting several exciting features. Signalling a concerning development in malware sophistication and diversity. This previously undocumented malware, named Trojan.MAC.RustDoor is crafted in Rust, a language less familiar to security analysts, thereby posing challenges in detection and analysis. The discovery underscores the evolving landscape of cyber threats and the need for heightened vigilance among Mac OS users and security practitioners alike.[/subscribe_to_unlock_form]
Summary:
Researcher has identified new threat targeting Mac OS users: a previously undocumented backdoor written in Rust, boasting several exciting features. Signalling a concerning development in malware sophistication and diversity. This previously undocumented malware, named Trojan.MAC.RustDoor is crafted in Rust, a language less familiar to security analysts, thereby posing challenges in detection and analysis. The discovery underscores the evolving landscape of cyber threats and the need for heightened vigilance among Mac OS users and security practitioners alike.[emaillocker id="1283"]
The backdoor, distributed under various guises such as Visual Studio updates, infiltrates systems through FAT binaries containing Mach-O files tailored for both x86_64 Intel and ARM architectures. It exhibits multiple variants denoted as Variant 1, 2, and Zero, each showcasing distinctive characteristics and capabilities. Leveraging Rust's syntax and semantics, the malware deploys a suite of commands to execute tasks, including gathering system information and uploading files to Command and Control (C&C) servers. Communication with these servers occurs through distinct endpoints, facilitating data exchange and task execution. Variant 1, observed since November 2023, serves as a testing version, featuring an embedded plist file aimed at ensuring persistence through LaunchAgents. Conversely, Variant 2, identified around the same time, introduces a more complex JSON configuration and an embedded Apple script for data exfiltration. These variant targets specific file types and user notes stored in SQLITE format, compressing, and transmitting them to C&C servers. Variant Zero, the earliest iteration identified in February 2023, lacks the sophistication of its successors, omitting the embedded script and configuration elements. Persistence mechanisms across variants include cronjobs, LaunchAgents, modifications to the ~/.zshrc file, and addition to the dock, underscoring the malware's resilience and adaptability.
Mac OS users and organizations should remain vigilant and adopt robust security measures, including regular software updates, endpoint protection, and user education on phishing and malware detection. Collaboration among cybersecurity researchers and industry stakeholders is imperative to monitor, analyze, and mitigate emerging threats effectively. Additionally, enhancing detection capabilities and sharing threat intelligence can bolster collective defenses against evolving malware tactics and strategies.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2024/02/alert-new-stealthy-rustdoor-backdoor.html
[/emaillocker]