MEDIUMMalware
Global

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

·Source: The Hacker News

Updated:

Executive Summary

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily

Analysis

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily
Source Attribution

Originally published by The Hacker News on Jul 30, 2026.

Related Threats