{"id":1131,"date":"2026-07-31T09:43:00","date_gmt":"2026-07-31T07:43:00","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=1131"},"modified":"2026-08-17T09:44:37","modified_gmt":"2026-08-17T07:44:37","slug":"dprk-linked-macos-malvertising-uses-fake-updates-to-deliver-crypto-stealing-malware","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2026\/07\/31\/dprk-linked-macos-malvertising-uses-fake-updates-to-deliver-crypto-stealing-malware\/","title":{"rendered":"DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running&nbsp;<strong><a href=\"https:\/\/thehackernews.com\/2026\/06\/north-korean-hackers-are-turning.html\" target=\"_blank\" rel=\"noreferrer noopener\">Contagious Interview<\/a><\/strong>&nbsp;campaign.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The defining aspect of the attack is that bogus macOS software update screen stealthily copies an attack command to the clipboard and then prompts the victim to execute it via the Terminal app, a known technique referred to as&nbsp;<a href=\"https:\/\/thehackernews.com\/2026\/07\/new-telepuz-malware-spreads-via.html\" target=\"_blank\" rel=\"noreferrer noopener\">ClickFix<\/a>.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2026\/07\/31\/dprk-linked-macos-malvertising-uses-fake-updates-to-deliver-crypto-stealing-malware\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2026\/07\/dprk-linked-macos-malvertising-uses.html\">DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware<\/a><span class=\"screen-reader-text\">: DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running&nbsp;Contagious Interview&nbsp;campaign. The defining aspect of the attack is&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[72,39],"class_list":["post-1131","post","type-post","status-publish","format-standard","hentry","category-malware","tag-72","tag-north-korea"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=1131"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1131\/revisions"}],"predecessor-version":[{"id":1132,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1131\/revisions\/1132"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=1131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=1131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=1131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}