North Korean threat actors are targeting macOS users through a sophisticated malvertising campaign that uses fake system update screens to trick victims into executing malicious terminal commands.
Key Points
- Attackers use a "ClickFix" technique to prompt users to copy and paste malicious terminal commands under the guise of a fake macOS system update.
- The malware utilizes "EtherHiding," a method that retrieves command-and-control server addresses from Ethereum smart contracts to ensure resilience against takedowns.
- Initial infection occurs when users click on compromised sponsored search results, moving away from the group's traditional fake job interview lures.
- The final payload includes an information stealer targeting 157 cryptocurrency wallets and a malicious browser extension designed to drain digital assets.
- The campaign is attributed to North Korean threat actors previously linked to the "Contagious Interview" cluster, also known as UNC5342.