Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Here’s what’s next for Zcash’s price after whale accumulation counters selling pressure

September 30, 2026

Senate inquiry chair asks OpenAI’s Altman and Anthropic’s Amodei to front Canberra hearing

September 30, 2026

Bitget had 30 minutes to contain its hack before $290 million started moving

September 30, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Lazarus Group Uses Extended Attributes for Code Smuggling in macOS
Lazarus Group Uses Extended Attributes for Code Smuggling in macOS
Security and Privacy

Lazarus Group Uses Extended Attributes for Code Smuggling in macOS

November 13, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A new technique by the Lazarus Advanced Persistent Threat (APT) group has been used by the threat actor to smuggle malicious code onto macOS systems, using custom extended attributes. 

This innovative method, observed by Group-IB, bypasses traditional security measures, enabling malicious code to remain concealed and undetected.

Extended attributes, often used to store additional file metadata, are now being leveraged by Lazarus to hide and execute malware on targeted systems.

Evolution of Malware Concealment

The group’s recent malware samples suggest they are experimenting with extended attributes to avoid detection, much like a previous technique used in 2020, where Bundlore adware concealed its payload in resource forks. However, Lazarus’s new approach takes advantage of extended attributes, which are more versatile in modern macOS systems.

Among the Lazarus-developed malware discovered was “RustyAttr,” a Trojan crafted using the Tauri framework. Tauri allows developers to build applications that blend a web frontend with a Rust backend, which has the potential to run stealthily on macOS.

By hiding malicious code within extended attributes and then executing it using Tauri’s built-in interface commands, Lazarus circumvents many antivirus protections. Notably, this malware remains fully undetected on VirusTotal.

Read more on macOS malware: Cthulhu Stealer Malware Targets macOS With Deceptive Tactics

Deceptive Tactics and User Distraction

The research also found that Lazarus’s malware includes various decoy elements, such as PDFs related to project development or cryptocurrency, and fake system messages.

The decoys are intended to mislead users while the malware executes in the background, fetching additional malicious scripts from command-and-control (C2) servers associated with Lazarus since 2024. Some files even referenced previous Lazarus campaigns, like the RustBucket malware from 2023.

See also  Crypto-Mining Botnet Goes After Misconfigured Docker APIs

Key findings from Group-IB’s analysis include:

  • Code smuggling using extended attributes, a technique not yet cataloged in the MITRE ATT&CK framework

  • The discovery of RustyAttr, a macOS trojan built with the Tauri framework

  • The use of fake decoys and dialogs to distract users while malicious scripts are executed

  • A moderate confidence level in attributing this activity to Lazarus, as no direct victims were identified

At present, Apple’s Gatekeeper prevents unsigned or unnotarized applications from running. However, if victims override these protections, they could unwittingly enable Lazarus’s malware to deploy. 

Cybersecurity experts urged users to stay cautious when prompted to download files from unfamiliar sources and to keep Gatekeeper protections enabled, as disabling these may leave macOS systems vulnerable to such attacks.

Image credit: DenPhotos / Shutterstock.com

Source link

Attributes code Extended Group Lazarus macOS Smuggling
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cboe, S&P Dow Jones open door for tokenized options under extended licensing deal

September 29, 2026

Ademco Security Group Launches UltraSenSync as Vision AI Redesigns Security and Facilities Work

September 29, 2026

Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach

September 28, 2026

Crypto scammers built an entire fake blockchain to steal over $2 million

September 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Coinbase’s reliance on AI for code sparks security concerns

September 4, 2025

Data reveals the new “sweet spot” for crypto in your portfolio as financial advisors flip aggressive on Bitcoin

January 14, 2026

Coinbase takes an interest in USDC – all you need to know

August 22, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Here’s what’s next for Zcash’s price after whale accumulation counters selling pressure

September 30, 2026

Senate inquiry chair asks OpenAI’s Altman and Anthropic’s Amodei to front Canberra hearing

September 30, 2026

Bitget had 30 minutes to contain its hack before $290 million started moving

September 30, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$83,350.00-0.18%
  • ethereumEthereum(ETH)$2,672.67-0.23%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$764.010.57%
  • rippleXRP(XRP)$1.510.60%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$119.020.51%
  • tronTRON(TRX)$0.3375440.91%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.032.72%
  • zcashZcash(ZEC)$1,403.541.11%