DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware post, juli 31, 2026augustus 17, 2026 Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily copies an attack command to the clipboard and then prompts the victim to execute it via the Terminal app, a known technique referred to as ClickFix. DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware: DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware malware 2026North Korea