Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean macOS Scam Uses Fake Updates to Steal Crypto

North Korean macOS Scam Uses Fake Updates to Steal Crypto

Posted on July 30, 2026 By CWS

A sophisticated macOS malvertising attack linked to North Korean threat actors has emerged, using fake software updates to distribute malware. This ongoing scheme, part of the notorious Contagious Interview campaign, employs deceptive tactics to trick users into executing malicious commands on their systems.

Deceptive Fake Updates

The malicious campaign initiates by redirecting users to counterfeit web pages that simulate a macOS update process. This fake update screen is designed to panic users into believing their system is malfunctioning, prompting them to follow instructions they might usually question.

According to AllSecure, the key feature of the attack is the use of a false macOS software update screen that covertly copies a command to the system clipboard. Users are then misled into pasting this command into the Terminal app, a tactic known as ClickFix.

Blockchain-Based Command and Control

A notable aspect of this operation is its use of blockchain-hosted command-and-control (C2) infrastructure. The attackers extract the active server address from an Ethereum smart contract, employing a method termed EtherHiding. This resilient approach has been previously utilized by North Korean actors in similar campaigns.

The malware’s ultimate goal is to execute remote code, allowing it to connect with the C2 server and retrieve additional malicious payloads. These include an information stealer targeting numerous cryptocurrency wallets and a harmful Chrome extension.

Unusual Infection Pathway

Unlike past Contagious Interview campaigns, which often started with job offers or coding tests, this campaign begins with a seemingly innocent web search. Users clicking on search results for specific products, like electrophoresis machines, are directed to malicious pages.

Once the fake update process concludes, users are instructed to open the Terminal app and paste the clipboard command. This command initiates the download and execution of a Node.js backdoor, maintaining persistence via a LaunchAgent and resolving the C2 address through Ethereum contracts.

Malware Impact and Future Threats

The malware leverages the EtherHiding method to deploy two primary payloads: a data harvester extracting information from various web browsers and cryptocurrency wallets, and a rogue Chrome extension that siphons funds from victims’ wallets.

Both the backdoor and browser extension activities are traced to a single wallet cluster, suggesting a coordinated effort by a singular actor. This campaign highlights the evolving tactics of DPRK-linked cyberattacks, expanding beyond traditional recruitment scams to broader web-based scenarios.

Christian Papathanasiou, co-founder and CEO of AllSecure, emphasizes the significance of this approach, noting that it broadens the threat landscape rather than replacing existing methods. As cyber threats continue to evolve, awareness and vigilance remain critical in safeguarding against such sophisticated attacks.

The Hacker News Tags:AllSecure, Blockchain, Contagious Interview, crypto theft, Cryptocurrency, Cybersecurity, Ethereum smart contract, EtherHiding, fake updates, macOS, Malvertising, Malware, North Korea, remote code execution, Terminal app

Post navigation

Previous Post: GenieLocker Ransomware Targets Multiple Systems
Next Post: Okta Expands Security with Permiso Acquisition

Related Posts

Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices The Hacker News
Microsoft Highlights Hotel Phishing Threat with Node.js Microsoft Highlights Hotel Phishing Threat with Node.js The Hacker News
CISA Flags VMware Vulnerability Amid Active Exploits CISA Flags VMware Vulnerability Amid Active Exploits The Hacker News
Beware of Android Spyware Disguised as Signal Encryption Plugin and ToTok Pro Beware of Android Spyware Disguised as Signal Encryption Plugin and ToTok Pro The Hacker News
Guardian Agents: Enhancing Identity Governance for AI Guardian Agents: Enhancing Identity Governance for AI The Hacker News
Critical Vulnerabilities in FatFs Impact Millions of Devices Critical Vulnerabilities in FatFs Impact Millions of Devices The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Bank of America to Acquire UK Cybersecurity Leader
  • Chrome 151 Update Fixes Critical Security Vulnerabilities
  • Okta Expands Security with Permiso Acquisition
  • North Korean macOS Scam Uses Fake Updates to Steal Crypto
  • GenieLocker Ransomware Targets Multiple Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Bank of America to Acquire UK Cybersecurity Leader
  • Chrome 151 Update Fixes Critical Security Vulnerabilities
  • Okta Expands Security with Permiso Acquisition
  • North Korean macOS Scam Uses Fake Updates to Steal Crypto
  • GenieLocker Ransomware Targets Multiple Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark