hacker-news · Crawled Jul 30, 2026

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

4 IoCs 1 Actors
Read original article ↗

AI Summary

A macOS malvertising campaign linked to North Korean threat actors has been identified, leveraging fake software update pages to trick users into executing a malicious Terminal command. The attack, part of the Contagious Interview campaign (UNC5342), uses social engineering to induce panic and prompt users to paste a clipboard-staged curl command, leading to malware deployment. The malware employs an EtherHiding technique, retrieving C2 server addresses from Ethereum smart contracts, and delivers a Node.js backdoor and a crypto-stealing payload targeting 157 cryptocurrency wallets and browser data.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 4 extracted

Type Value Detail
Domain rg-telemetry[.]sbs Details →
Domain th-updates[.]sbs Details →
Filename Secure Preferences Details →
GitHub Repo AllSecure/contagious-interview-analysis Details →

MITRE ATT&CK TTPs 5 techniques