Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-30 ยท updated: 2026-08-18 ยท tags: [cyber, digest-2026-07-31, north-korea, dprk, macos, malvertising, crypto-theft, contagions-interview] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Summary

North Korean threat actors have been attributed to a sophisticated macOS malvertising campaign as part of the long-running Contagious Interview campaign. Victims are redirected to fake pages displaying a full-screen macOS software update sequence that stealthily copies an attack command to the clipboard and prompts execution via Terminal (ClickFix technique). The campaign uses blockchain-hosted C2, extracting live server addresses from Ethereum smart contracts.

Key Details

  • Date: 2026-07-30
  • Source: The Hacker News
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Threat Actor: DPRK (North Korea) โ€” Contagious Interview campaign
  • Target Platform: macOS
  • Technique: Malvertising โ†’ fake software update โ†’ ClickFix (clipboard attack command)
  • C2 Infrastructure: Blockchain-hosted (Ethereum smart contracts)
  • Payload: Crypto-stealing malware
  • Campaign: Long-running "Contagious Interview"

Source

See Also

  • North Korea's Lazarus Group Sharing Tools with Ransomware Hackers
  • Hackers Exploit AnySign4PC via Compromised Korean Websites to Install Backdoors
  • SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT