Close Menu
NCIJ Network NCIJ Network
    What's Hot

    India wants to cuts its reliance on overseas strawberry varieties

    July 30, 2026

    The cost and burden of avoiding ‘forever chemicals’ should not fall on parents | Pfas

    July 30, 2026

    Why is US GDP growth slowing, and how can it be reversed? | International Trade News

    July 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • India wants to cuts its reliance on overseas strawberry varieties
    • The cost and burden of avoiding ‘forever chemicals’ should not fall on parents | Pfas
    • Why is US GDP growth slowing, and how can it be reversed? | International Trade News
    • Andy Burnham to give regional mayors share of income tax
    • Burnham to free mayors from ‘Treasury death grip’ with new devolved powers | Devolution
    • Amazon increases AI infrastructure spending to $220bn this year
    • A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
    • DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, July 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 30, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 30, 2026Malvertising / Cryptocurrency

    Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.

    The defining aspect of the attack is that bogus macOS software update screen stealthily copies an attack command to the clipboard and then prompts the victim to execute it via the Terminal app, a known technique referred to as ClickFix.

    “The experience is designed to induce panic,” AllSecure said in a report shared with The Hacker News. “The computer appears frozen or rebooting, so a user who believes the OS has failed follows instructions they would otherwise find suspicious.”

    The campaign is also noteworthy for its use of blockchain-hosted command-and-control (C2), with the malware extracting the live server address from an Ethereum smart contract. This takedown-resistant approach, referred to as EtherHiding, has been put to use by North Korean threat actors in prior campaigns associated with Contagious Interview (aka UNC5342).

    Cybersecurity

    The end goal of the attacks is to facilitate remote code execution, allowing the implant to poll the C2 server and fetch two additional payloads, an information stealer capable of targeting 157 cryptocurrency wallets and a malicious Chrome extension.

    The attack chain is a departure from typical Contagious Interview campaigns in that the starting point involves clicking on a search result for an unspecified target company. As soon as the website opens, the browser displays the full-screen macOS reboot message, giving the impression that a software update was underway, while stealthily setting the stage for the next phase of the infection.

    Once the fake update sequence completes, the fake page prompts the user to open the Terminal app and paste an already copied command into the system’s clipboard. Interestingly, any attempts to reproduce this sequence do not yield the same result, meaning the activation is intended to be single-use.

    What’s interesting here is that the initial lure was not a suspicious job offer, a video assessment, or a coding test, all of which have been various methods the Contagious Interview cluster has employed in the past. Instead, it begins with a seemingly harmless web search.

    In the case observed by AllSecure, the victim is said to have been searching for electrophoresis machines and clicked on a sponsored result for a company that appeared to sell them. The infection sequence begins immediately after the fake page loads on their browser.

    The command pasted into Terminal is a curl command designed to fetch the next-stage malware, leading to the execution of a Node.js backdoor that uses a LaunchAgent for persistence and calls an Ethereum contract to resolve the C2 server address. The implant is configured to check in with the server every five minutes and execute any JavaScript code returned by it.

    Cybersecurity

    The EtherHiding mechanism serves as a conduit for two payloads –

    • An information stealer that harvests data from web browsers (Chrome, Brave, Edge, Firefox, Opera, and Vivaldi), 157 cryptocurrency wallets, as well as SSH, AWS, Azure, and npm keys
    • A malicious “Google Drive Offline” extension that’s sideloaded into the browser by patching Chrome’s Secure Preferences file and is used to drain a victim’s wallet.

    Two Ethereum addresses are embedded into the malware, both acting as EtherHiding configuration responsible for fetching the actual C2 servers: “rg-telemetry[.]sbs/api” and “th-updates[.]sbs/analytics.”

    “Each contract was created by a throwaway wallet running an identical four-step script: funded with ~0.0126 ETH, deploy the contract, write the config, forward the leftover ~0.006 ETH onward, then abandon the wallet,” AllSecure said. “The pattern suggests an operator that has industrialised deployment: fund, deploy, configure, drain leftovers, abandon, repeat.”

    Further analysis has determined that both the backdoor and the browser-extension drainer are funded from the same wallet cluster, indicating that the activity is the work of a single actor.

    “The delivery context is also worth noting: DPRK-linked campaigns are often described through the lens of fake job interviews and developer recruitment, but this case shows the same operational logic appearing in a broader browsing scenario,” Christian Papathanasiou, co-founder and CEO of AllSecure, said. “That does not replace the fake-job pattern; it expands the threat model.”

    CryptoStealing deliver DPRKLinked Fake macOS Malvertising Malware updates
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AI Harnesses Burst With Potential Exploit Opps

    VMware fixes three critical flaws allowing auth bypass, VM escapes

    Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

    Timeless Compliance: Why Better Questions Beat Bigger Frameworks

    ShinyHunters claims Brinks Home breach, threatens to leak stolen data

    Analog Devices discloses data breach, says operations unaffected

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    India wants to cuts its reliance on overseas strawberry varieties

    July 30, 2026

    The cost and burden of avoiding ‘forever chemicals’ should not fall on parents | Pfas

    July 30, 2026

    Why is US GDP growth slowing, and how can it be reversed? | International Trade News

    July 30, 2026

    Andy Burnham to give regional mayors share of income tax

    July 30, 2026
    Latest Posts

    Advancing the next era of national science

    July 22, 2026

    Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

    July 22, 2026

    Most bus fares in England to be capped at £2 from January

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    India wants to cuts its reliance on overseas strawberry varieties

    July 30, 2026

    The cost and burden of avoiding ‘forever chemicals’ should not fall on parents | Pfas

    July 30, 2026

    Why is US GDP growth slowing, and how can it be reversed? | International Trade News

    July 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.