DPRK-Linked macOS Malvertising Campaign Exploits Fake Updates to Deploy Crypto-Stealing Malware
A DPRK-linked macOS malvertising campaign uses fake software updates to trick users into executing malicious commands via Terminal, delivering crypto-stealing malware with Ethereum-based command-and-control infrastructure. The attack employs EtherHiding techniques to maintain resilience and includes payloads targeting cryptocurrency wallets and browser extensions.
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.
The defining aspect of the attack is that bogus macOS software update screen stealthily
*** END OF TRANSMISSION ***