Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

post, juli 31, 2026augustus 17, 2026

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.

The defining aspect of the attack is that bogus macOS software update screen stealthily copies an attack command to the clipboard and then prompts the victim to execute it via the Terminal app, a known technique referred to as ClickFix.

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware: DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
malware 2026North Korea

Bericht navigatie

Previous post
Next post

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes