Tuesday, February 25, 2025
HomeAppleRust Infostealer Malware Attacks macOS Sonoma Ahead of Public Release

Rust Infostealer Malware Attacks macOS Sonoma Ahead of Public Release

Published on

SIEM as a Service

Follow Us on Google News

Based on recent reports, it was discovered that there has been info stealer malware that affects both Windows and macOS platforms. The malware can steal crypto wallets, passwords, and browser data.

This new variant of malware is found to be written in Rust programming language, which was named “realst.”

The analysis stated that this malware is capable of targeting Apple’s upcoming macOS versionSonoma.”

Realst Distribution

The initial distribution of this malware involves fake advertising of blockchain games like Brawl Earth, WildWorld, Dawnland, Destruction, Evolion, etc.

Every blockchain game version was hosted on its own website along with the Twitter and Discord accounts.

Blockchain game and its Twitter account (Source: SentinelOne)

Malicious Installers of Realst

The .pkg installer in some of the distributed malware consisted of a malicious Mach-O and related scripts, including game.py, installer.py, and uninstall. sh. The game.py is a cross-platform Firefox infostealer.

The installer.py is a copy of the chain breaker project that is capable of extracting passwords, keys, and certificates from the macOS keychain database. The uninstall. sh did not have any malicious behavior.

Contents of Evolion.pkg installer (Source: SentinelOne)

Static Analysis & Dynamic Analysis

These malware are similar to the other cross-variant malware and are easily detectable. In some cases, this malware uses different API calls and some dependencies.

However, all of these malware have the same goal of exfiltrating the browser data, crypto wallets, and keychain databases.

Static analysis showed that some variants make an attempt to grab the user’s password through osascript and AppleScript Spoofing.

Researchers have analyzed over 16 variants of this malware across 59 samples and have divided them into four families as A, B, C and D.

Variant Family A – Uses AppleScript Spoofing to steal user’s admin password in clear text.

Variant Family B – These samples break up the strings to evade static detection.

Variant Family C – Attempts to hide strings for AppleScript spoofing and have references to chain breaker

Variant Family D – No static artifacts for osascript spoofing, and password scraping is handled by the Terminal window via the get_keys_with_access function, which is passed immediately to sym.realst::utils::get_kc_keys for attempting to dump passwords from keychains.

SentinelOne has published a complete report including IOCs about these malware variants and their methods.

Users are recommended to be vigilant towards these blockchain games and verify each game’s legitimacy before downloading them.

Stay up-to-date with the latest Cyber Security News; follow us on GoogleNewsLinkedinTwitterand Facebook.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Google Issues Warning on Phishing Campaigns Targeting Higher Education Institutions

Google, in collaboration with its Mandiant Threat Intelligence team, has issued a warning about...

TgToxic Android Malware Updated it’s Features to Steal Login Credentials

The TgToxic Android malware, initially discovered in July 2022, has undergone significant updates, enhancing...

Hackers Exploiting Cisco Small Business Routers RCE Vulnerability Deploying Webshell

A critical remote code execution (RCE) vulnerability, CVE-2023-20118, affecting Cisco Small Business Routers, has...

Malicious npm Package Targets Developers for Supply Chain Attack

The Socket Research Team has uncovered a malicious npm package@ton-wallet/create designed to steal sensitive...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Google Issues Warning on Phishing Campaigns Targeting Higher Education Institutions

Google, in collaboration with its Mandiant Threat Intelligence team, has issued a warning about...

TgToxic Android Malware Updated it’s Features to Steal Login Credentials

The TgToxic Android malware, initially discovered in July 2022, has undergone significant updates, enhancing...

Hackers Exploiting Cisco Small Business Routers RCE Vulnerability Deploying Webshell

A critical remote code execution (RCE) vulnerability, CVE-2023-20118, affecting Cisco Small Business Routers, has...