Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

‘I Want More Regulation, And I Want It Now’

May 17, 2025

VanEck and Securitize Launch Tokenized Treasury Fund on Ethereum, Solana and Two Other Chains

May 17, 2025

UBS reveals wealthy investors increasing crypto allocations to 5%, echoing Bitwise

May 17, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Is A Bitcoin Supercycle Imminent?

    May 17, 2025

    Bitcoin Price Consolidates Around $103,000-Here’s What May Happen if it Rises & Secures above $105,000

    May 17, 2025

    Bitcoin Flirting With Danger As BTC Faces Major Resistance Level, Says Trader Jason Pizzino – Here’s His Outlook

    May 16, 2025

    Bitcoin (BTC) Price Bulls Face $120M Challenge in Extending ‘Stair-Step’ Uptrend

    May 16, 2025

    Ethereum Building Up Momentum Before a Massive Breakout, Predicts Michaël van de Poppe – Here Are His Targets

    May 17, 2025

    Ethereum Looks Ready To Break Out Of 4-Year Consolidation, Analyst Says Price Will ‘Go Insane’

    May 17, 2025

    Blockchain-focused BTCS Inc. to raise $57.8M for Ethereum buys – Impact on ETH?

    May 16, 2025

    Bitcoin Primed To Skyrocket to $120,000, According to Crypto Analyst – But There’s a Catch

    May 16, 2025

    VanEck and Securitize Launch Tokenized Treasury Fund on Ethereum, Solana and Two Other Chains

    May 17, 2025

    Avalanche [AVAX] usage jumps 221% – 3 factors will decide if $25 holds

    May 17, 2025

    Ethereum Multi-Year Consolidation Could Spark A Parabolic Move – Details

    May 17, 2025

    VIRTUAL corrects 13%, but bullish sentiment remains high – What’s next?

    May 16, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    ‘I Want More Regulation, And I Want It Now’

    May 17, 2025

    VanEck and Securitize Launch Tokenized Treasury Fund on Ethereum, Solana and Two Other Chains

    May 17, 2025

    UBS reveals wealthy investors increasing crypto allocations to 5%, echoing Bitwise

    May 17, 2025

    Bitcoin DeFi protocol Liquidium’s rebrand and staking model propel LIQ token to new heights

    May 17, 2025
  • DeFi

    Bitcoin DeFi protocol Liquidium’s rebrand and staking model propel LIQ token to new heights

    May 17, 2025

    BlackRock’s BUIDL fund added to Eular for collateral use

    May 17, 2025

    Here’s why Maple Finance’s SYRUP token is surging

    May 16, 2025

    EOS price eyes 20% surge as multiple bullish patterns emerge

    May 16, 2025

    Sygnum Bank Adds Staked SOL as Collateral

    May 16, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Eric Trump Token Skyrockets 6,200% – Is a Solana Rug Pull Next

    May 17, 2025

    Ripple Board Member Says Blockchain Is Unbundling Banks

    May 17, 2025

    Tinian Defies Veto, Unveils First U.S. Public USD Stablecoin on eCash Network

    May 17, 2025

    South Korea’s Leading Cryptocurrency Exchange Upbit Releases New Listing Announcement! Here’s the Latest Listed Altcoin

    May 17, 2025

    Coinbase Offers $20m Bounty to Take Down Cybercrime Ring Behind Hack

    May 16, 2025

    How an insider-led breach sparked a costly scam at Coinbase

    May 16, 2025

    New ‘Chihuahua Stealer’ Targets Browser Data and Crypto Wallets

    May 14, 2025

    FreeDrain Phishing Scam Drains Crypto Hobbyists’ Wallets

    May 12, 2025

    ‘I Want More Regulation, And I Want It Now’

    May 17, 2025

    VanEck and Securitize Launch Tokenized Treasury Fund on Ethereum, Solana and Two Other Chains

    May 17, 2025

    UBS reveals wealthy investors increasing crypto allocations to 5%, echoing Bitwise

    May 17, 2025

    Bitcoin DeFi protocol Liquidium’s rebrand and staking model propel LIQ token to new heights

    May 17, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    NEXTGEN DIGITAL CLOSES SECOND TRANCHE OF THE NON-BROKERED PRIVATE PLACEMENT OF SPECIAL WARRANTS AND COMMON SHARES

    May 17, 2025

    Europe Medium Voltage Fuse Market Sales Forecast to Hit USD 526.7 Million by 2034 with 4.6% CAGR – Outlook by Transparency Market Research

    May 17, 2025

    $TRUMP Coin Dinner: High Stakes, Hefty Price Tags, and Heated Allegations

    May 16, 2025

    Junction Gate Field-Effect Transistor (JFET) Market is Gaining Global Traction | Leading Players: Microsemi, Infineon Technologies AG

    May 16, 2025

    Solana Shooter Game ‘Nyan Heroes’ Shuts Down Amid Funding Issues

    May 17, 2025

    USD₮ Goes Live on LINE Messenger, Driving Asia’s Stablecoin Growth

    May 16, 2025

    ‘MapleStory N’ Game Launches on Avalanche With Surging NXPC Token

    May 16, 2025

    Why crypto games shouldn’t monetize too early

    May 16, 2025

    ‘I Want More Regulation, And I Want It Now’

    May 17, 2025

    VanEck and Securitize Launch Tokenized Treasury Fund on Ethereum, Solana and Two Other Chains

    May 17, 2025

    UBS reveals wealthy investors increasing crypto allocations to 5%, echoing Bitwise

    May 17, 2025

    Bitcoin DeFi protocol Liquidium’s rebrand and staking model propel LIQ token to new heights

    May 17, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    ‘I Want More Regulation, And I Want It Now’

    May 17, 2025

    The History of Crypto Taxes in the US

    May 17, 2025

    U.S. Senate’s Stablecoin Push Still Alive as Bill May Return to Floor: Sources

    May 17, 2025

    Judge targets central figures in LIBRA scandal with asset freeze; Milei’s financial ties under review

    May 17, 2025

    UBS reveals wealthy investors increasing crypto allocations to 5%, echoing Bitwise

    May 17, 2025

    Basel Medical Group to add $1B in Bitcoin to treasury amid falling share prices

    May 17, 2025

    Panama City mayor hints at Bitcoin reserve following meeting with El Salvador advisors

    May 16, 2025

    Chainlink praises SEC’s guidelines, setting stage for crypto integration in institutional finance

    May 16, 2025

    ‘I Want More Regulation, And I Want It Now’

    May 17, 2025

    VanEck and Securitize Launch Tokenized Treasury Fund on Ethereum, Solana and Two Other Chains

    May 17, 2025

    UBS reveals wealthy investors increasing crypto allocations to 5%, echoing Bitwise

    May 17, 2025

    Bitcoin DeFi protocol Liquidium’s rebrand and staking model propel LIQ token to new heights

    May 17, 2025
  • Analysis

    Analyst Says Top-20 Altcoin Primed To Explode by 85%+ Eventually, Updates Outlook on Bitcoin and dogwifhat

    May 17, 2025

    Dogecoin On-Chain Activity Hits 6-Month High, Eyes On $0.30 Flip or Breakdown?

    May 16, 2025

    Breakout to $28 Coming Soon?

    May 16, 2025

    New Decentralized Gaming Token Skyrockets Following Binance Listing

    May 16, 2025

    Robinhood Rival eToro Goes Live on Nasdaq After Raising $620,000,000 in IPO

    May 16, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    Users Taunt Grok After xAI Says Modifications Were Made to Spit out ‘White Genocide’ Claim

    May 16, 2025

    What Is Base? The Ethereum Layer-2 Network Launched by Coinbase

    April 29, 2025

    What Is ‘Idle Mine’? This Free iOS and Android Game Pays Real Bitcoin

    April 20, 2025

    US Crypto Taxes in 2025: What You Need to Know

    April 4, 2025

    Coinbase CEO wants to hire DOGE staff to help improve the global financial system

    May 16, 2025

    FTX creditors poised to receive $5B by May 30 in latest distribution round

    May 16, 2025

    Coinbase resists $20 million Bitcoin ransom demand after insider-led data breach

    May 15, 2025

    Bitget Wallet launches new crypto in-app marketplace with access to over 300 brands

    May 15, 2025

    ‘I Want More Regulation, And I Want It Now’

    May 17, 2025

    VanEck and Securitize Launch Tokenized Treasury Fund on Ethereum, Solana and Two Other Chains

    May 17, 2025

    UBS reveals wealthy investors increasing crypto allocations to 5%, echoing Bitwise

    May 17, 2025

    Bitcoin DeFi protocol Liquidium’s rebrand and staking model propel LIQ token to new heights

    May 17, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»Lazarus Group Uses Extended Attributes for Code Smuggling in macOS
Security and Privacy

Lazarus Group Uses Extended Attributes for Code Smuggling in macOS

November 24, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A recent development in the cybersecurity landscape has revealed a new technique utilized by the Lazarus Advanced Persistent Threat (APT) group to infiltrate macOS systems with malicious code. This innovative method, detected by Group-IB, involves the use of custom extended attributes to smuggle and execute malware, evading traditional security measures and remaining undetected.

Extended attributes, typically employed to store additional file metadata, are now being leveraged by Lazarus to conceal and run malicious code on targeted macOS systems. This evolution in malware concealment marks a significant shift in the group’s tactics, as they experiment with new ways to bypass detection. Similar to a technique observed in 2020 where Bundlore adware concealed its payload in resource forks, Lazarus’s approach using extended attributes offers increased versatility on modern macOS systems.

Among the malware samples attributed to Lazarus is “RustyAttr,” a Trojan developed using the Tauri framework. Tauri enables developers to create applications that integrate a web frontend with a Rust backend, allowing for stealthy execution on macOS. By embedding malicious code within extended attributes and leveraging Tauri’s interface commands to execute it, Lazarus can evade many antivirus protections, with the malware remaining undetected on VirusTotal.

In addition to utilizing extended attributes for code smuggling, Lazarus’s malware incorporates deceptive tactics to distract and mislead users. Decoy elements such as project development-related PDFs and fake system messages are designed to divert attention while the malware operates in the background, fetching additional malicious scripts from Lazarus’s command-and-control servers. Some files even reference previous Lazarus campaigns, adding to the deception.

Key findings from Group-IB’s analysis include the use of extended attributes for code smuggling, the discovery of RustyAttr trojan built with the Tauri framework, the deployment of fake decoys and dialogs for user distraction, and a moderate confidence level in attributing this activity to Lazarus. While Apple’s Gatekeeper provides protection against unsigned or unnotarized applications, users are advised to exercise caution when downloading files from unfamiliar sources and to keep Gatekeeper protections enabled to prevent macOS systems from being vulnerable to such attacks.

See also  Lazarus Targets South Korea with Malicious Docs

As cybersecurity experts emphasize vigilance and adherence to security protocols, it is crucial for users to remain cautious and informed about potential threats targeting macOS systems. By staying informed and maintaining security measures, users can safeguard their devices against sophisticated cyber threats like those orchestrated by the Lazarus APT group.

Attributes Code Extended Group Lazarus macOS Smuggling
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Basel Medical Group to add $1B in Bitcoin to treasury amid falling share prices

May 17, 2025

Coinbase Offers $20m Bounty to Take Down Cybercrime Ring Behind Hack

May 16, 2025

How an insider-led breach sparked a costly scam at Coinbase

May 16, 2025

New ‘Chihuahua Stealer’ Targets Browser Data and Crypto Wallets

May 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Man Gets 12.5 Years for Running Crypto Mixer

November 24, 2024

Advance Your Career with Accredited Blockchain Certifications

March 28, 2025

Wall Street Pepe Presale Reaches $45M Milestone for New Trading Insights Platform

January 12, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

‘I Want More Regulation, And I Want It Now’

May 17, 2025

VanEck and Securitize Launch Tokenized Treasury Fund on Ethereum, Solana and Two Other Chains

May 17, 2025

UBS reveals wealthy investors increasing crypto allocations to 5%, echoing Bitwise

May 17, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.