Fake macOS update pages drop crypto stealers in DPRK campaign

North Korea-linked actors are using fake full-screen macOS updates to push ClickFix-style clipboard attacks.

CSBadmin
1 Min Read

A macOS malvertising operation that pushes cryptocurrency-stealing malware through phony full-screen update screens has been attributed to North Korean hackers. Security firm AllSecure says the campaign is a fresh spin on the long-running Contagious Interview operation.

The attack starts with a search result. In the observed case, a victim searching for electrophoresis machines clicked a sponsored link, and the page immediately displayed a fake macOS reboot sequence. The bogus update screen copied an attack command to the clipboard and prompted the victim to paste it into Terminal, a ClickFix technique designed to induce panic.

The command fetches a Node.js backdoor that uses a LaunchAgent for persistence and resolves its command-and-control address from an Ethereum smart contract, a takedown-resistant approach known as EtherHiding. The implant checks in every five minutes and executes JavaScript returned by the server.

Two payloads arrive after the backdoor: a stealer that harvests 157 crypto wallet types plus browser, SSH, AWS, Azure, and npm keys, and a fake Google Drive Offline extension that empties wallets by rewriting Chrome’s Secure Preferences file. AllSecure said the deployment pattern suggests an operator that has industrialized the process, funding contracts with throwaway wallets and abandoning them after configuration.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.