Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean Cyber Campaign Targets Crypto Wallets

North Korean Cyber Campaign Targets Crypto Wallets

Posted on July 31, 2026 By CWS

A sophisticated cyber operation linked to North Korea is targeting macOS users through deceptive update notifications. This campaign is designed to infiltrate systems by posing as legitimate macOS updates, ultimately installing malicious software.

The operation specifically seeks to compromise cryptocurrency wallets, browser data, and developer credentials. The attack method begins with a fake browser page that mimics a frozen or rebooting Mac screen, prompting users to enter a command in Terminal, which initiates the malware installation process.

Details of the Cyber Attack

Researchers at AllSecure uncovered this campaign while investigating a separate incident involving malvertising. The tactics used in this campaign have been connected to North Korean groups, such as UNC5342, expanding beyond typical phishing attempts aimed at developers and job seekers.

This attack is particularly dangerous due to its combination of social engineering, remote access malware, and the use of blockchain-based infrastructure to control the malware, making it a persistent threat.

Technical Analysis of the Malware

Once the malicious command is executed, a dropper installs Node.js and launches a remote access trojan. Unlike traditional malware, this does not rely on a fixed server but uses Ethereum smart contracts for command-and-control instructions, a method known as EtherHiding.

This approach allows attackers to update their infrastructure without altering the malware on victim devices. The backdoor checks in every five minutes and can execute JavaScript, maintaining persistence through modified system files and hidden cache files.

Impact and Recommendations

The malware collects sensitive data from 157 cryptocurrency wallets, browser credentials, and development environments, posing significant risks to developers and organizations. It also installs a malicious Chrome extension that grants extensive permissions, enabling continuous monitoring and control of browser activities.

AllSecure tracked transactions amounting to 464.80 ETH, valued at approximately $890,000, linked to this campaign. Organizations are urged to isolate compromised devices, reset credentials from secure systems, and ensure cryptocurrency assets are transferred to safe wallets.

Users should be cautious of any macOS update requests that require Terminal commands, a practice not associated with legitimate updates. This awareness is crucial in preventing further compromises from similar threats.

To build resilience against such threats, organizations are advised to strengthen their security operations centers and utilize platforms like ANY.RUN for safe malware analysis.

Cyber Security News Tags:Blockchain, crypto wallets, Cybersecurity, developer credentials, Ethereum, macOS, Malware, North Korea, remote access, social engineering

Post navigation

Previous Post: HollowFrame and Matryoshka Backdoor Target Law Firm
Next Post: Cyber Attacks Hit Central Asia Using New Malware Tools

Related Posts

Flipper One: New Modular Linux Cyberdeck Unveiled Flipper One: New Modular Linux Cyberdeck Unveiled Cyber Security News
LockBit Operators Using Stealthy DLL Sideloading Technique to Load Malicious App as Legitimate One LockBit Operators Using Stealthy DLL Sideloading Technique to Load Malicious App as Legitimate One Cyber Security News
Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens Cyber Security News
Six RCE Vulnerabilities Threaten AI Workflow Servers Six RCE Vulnerabilities Threaten AI Workflow Servers Cyber Security News
BugHunter Toolkit Enhances Vulnerability Detection BugHunter Toolkit Enhances Vulnerability Detection Cyber Security News
Apache Flink Vulnerability Risks Remote Code Execution Apache Flink Vulnerability Risks Remote Code Execution Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark