A sophisticated macOS malvertising attack linked to North Korean threat actors has emerged, using fake software updates to distribute malware. This ongoing scheme, part of the notorious Contagious Interview campaign, employs deceptive tactics to trick users into executing malicious commands on their systems.
Deceptive Fake Updates
The malicious campaign initiates by redirecting users to counterfeit web pages that simulate a macOS update process. This fake update screen is designed to panic users into believing their system is malfunctioning, prompting them to follow instructions they might usually question.
According to AllSecure, the key feature of the attack is the use of a false macOS software update screen that covertly copies a command to the system clipboard. Users are then misled into pasting this command into the Terminal app, a tactic known as ClickFix.
Blockchain-Based Command and Control
A notable aspect of this operation is its use of blockchain-hosted command-and-control (C2) infrastructure. The attackers extract the active server address from an Ethereum smart contract, employing a method termed EtherHiding. This resilient approach has been previously utilized by North Korean actors in similar campaigns.
The malware’s ultimate goal is to execute remote code, allowing it to connect with the C2 server and retrieve additional malicious payloads. These include an information stealer targeting numerous cryptocurrency wallets and a harmful Chrome extension.
Unusual Infection Pathway
Unlike past Contagious Interview campaigns, which often started with job offers or coding tests, this campaign begins with a seemingly innocent web search. Users clicking on search results for specific products, like electrophoresis machines, are directed to malicious pages.
Once the fake update process concludes, users are instructed to open the Terminal app and paste the clipboard command. This command initiates the download and execution of a Node.js backdoor, maintaining persistence via a LaunchAgent and resolving the C2 address through Ethereum contracts.
Malware Impact and Future Threats
The malware leverages the EtherHiding method to deploy two primary payloads: a data harvester extracting information from various web browsers and cryptocurrency wallets, and a rogue Chrome extension that siphons funds from victims’ wallets.
Both the backdoor and browser extension activities are traced to a single wallet cluster, suggesting a coordinated effort by a singular actor. This campaign highlights the evolving tactics of DPRK-linked cyberattacks, expanding beyond traditional recruitment scams to broader web-based scenarios.
Christian Papathanasiou, co-founder and CEO of AllSecure, emphasizes the significance of this approach, noting that it broadens the threat landscape rather than replacing existing methods. As cyber threats continue to evolve, awareness and vigilance remain critical in safeguarding against such sophisticated attacks.
