hacker-news · Crawled Jul 30, 2026
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
4 IoCs 1 Actors
Read original article ↗
AI Summary
A macOS malvertising campaign linked to North Korean threat actors has been identified, leveraging fake software update pages to trick users into executing a malicious Terminal command. The attack, part of the Contagious Interview campaign (UNC5342), uses social engineering to induce panic and prompt users to paste a clipboard-staged curl command, leading to malware deployment. The malware employs an EtherHiding technique, retrieving C2 server addresses from Ethereum smart contracts, and delivers a Node.js backdoor and a crypto-stealing payload targeting 157 cryptocurrency wallets and browser data.
AI-extracted · verify before operational use