RustDoor Backdoor
Summary
Named RustDoor, the malware poses as Visual Studio supports both Intel and Arm architectures and has been circulating since November 2023, managing to evade detection for multiple months. Upon establishing itself on compromised systems, the malware copies targeted documents and data to a concealed folder compresses them into a ZIP archive and then transmits them to the Command-and-Control (C&C) server. Researchers also found that RustDoors configuration file allows for the impersonation of different applications, with options to customize a spoofed administrator password dialog. Once attackers gain access through a backdoor, they may encrypt the users files and demand a ransom for their release, causing significant disruption and financial loss. To mitigate these risks, it is crucial for users to employ robust cybersecurity measures, including regular software updates, the use of reputable antivirus programs, and practicing safe online behaviors to avoid falling victim to backdoor malware attacks.