< BACK TO NEWS
negativeSYS.SOURCE: The Hacker News2026-07-30T23:48:24+05:30

DPRK-Linked macOS Malvertising Campaign Exploits Fake Updates to Deploy Crypto-Stealing Malware

A DPRK-linked macOS malvertising campaign uses fake software updates to trick users into executing malicious commands via Terminal, delivering crypto-stealing malware with Ethereum-based command-and-control infrastructure. The attack employs EtherHiding techniques to maintain resilience and includes payloads targeting cryptocurrency wallets and browser extensions.

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.

The defining aspect of the attack is that bogus macOS software update screen stealthily

Read original article

*** END OF TRANSMISSION ***