AUTO-UPDATED

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

North Korean threat actors are targeting macOS users through a sophisticated malvertising campaign that uses fake system update screens to trick victims into executing malicious terminal commands.

Key Points

  • Attackers use a "ClickFix" technique to prompt users to copy and paste malicious terminal commands under the guise of a fake macOS system update.
  • The malware utilizes "EtherHiding," a method that retrieves command-and-control server addresses from Ethereum smart contracts to ensure resilience against takedowns.
  • Initial infection occurs when users click on compromised sponsored search results, moving away from the group's traditional fake job interview lures.
  • The final payload includes an information stealer targeting 157 cryptocurrency wallets and a malicious browser extension designed to drain digital assets.
  • The campaign is attributed to North Korean threat actors previously linked to the "Contagious Interview" cluster, also known as UNC5342.

Why it Matters

This campaign demonstrates an evolution in North Korean cyber operations by expanding from targeted recruitment lures to broader, opportunistic malvertising attacks. The use of blockchain-based infrastructure and sophisticated social engineering highlights a growing threat to macOS users and cryptocurrency holders.
Internet Published by info@thehackernews.com (The Hacker News)
Read original