New RustyAttr Malware Targets macOS Through Extended Attribute Abuse
Threat actors have been discovered using a novel method to smuggle a new malware known as RustyAttr by abusing extended attributes for macOS files.
Citing tactical and infrastructure commonalities seen in relation to previous efforts, such as RustBucket, the Singaporean cybersecurity firm has linked the new activity with a moderate degree of confidence to the notorious Lazarus Group, which is associated with North Korea.
Extended attributes are extra metadata linked to files and directories that can be retrieved with the use of a specific command known as xattr. They are frequently used to hold data like file size, timestamps, and permissions that are not included in the normal attributes read more about New RustyAttr Malware Targets macOS Through Extended Attribute Abuse.
Get up...

