type: incident ยท created: 2026-07-30 ยท updated: 2026-08-18 ยท tags: [cyber, digest-2026-07-31, north-korea, dprk, macos, malvertising, crypto-theft, contagions-interview] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Summary
North Korean threat actors have been attributed to a sophisticated macOS malvertising campaign as part of the long-running Contagious Interview campaign. Victims are redirected to fake pages displaying a full-screen macOS software update sequence that stealthily copies an attack command to the clipboard and prompts execution via Terminal (ClickFix technique). The campaign uses blockchain-hosted C2, extracting live server addresses from Ethereum smart contracts.
Key Details
- Date: 2026-07-30
- Source: The Hacker News
- Reliability: Tier 2/4 โ Established cyber journalism
- Threat Actor: DPRK (North Korea) โ Contagious Interview campaign
- Target Platform: macOS
- Technique: Malvertising โ fake software update โ ClickFix (clipboard attack command)
- C2 Infrastructure: Blockchain-hosted (Ethereum smart contracts)
- Payload: Crypto-stealing malware
- Campaign: Long-running "Contagious Interview"
Source
See Also
- North Korea's Lazarus Group Sharing Tools with Ransomware Hackers
- Hackers Exploit AnySign4PC via Compromised Korean Websites to Install Backdoors
- SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT