North Korea-linked threat actors launched a macOS malvertising campaign that uses a fake full-screen update page and ClickFix-style clipboard abuse to trick victims into running malicious Terminal commands. The campaign, tied to Contagious Interview and EtherHiding, delivers a Node.js backdoor, an info stealer, and a malicious Chrome extension targeting cryptocurrency wallets and cloud credentials. #ContagiousInterview #UNC5342 #EtherHiding #ClickFix
Keypoints
- The campaign uses malicious sponsored search results to lure macOS users to a fake update page.
- A bogus reboot screen copies a command to the clipboard and prompts the victim to run it in Terminal.
- The malware uses EtherHiding by pulling C2 details from Ethereum smart contracts.
- The payload includes a Node.js backdoor, an information stealer, and a malicious Chrome extension.
- The stealer targets 157 cryptocurrency wallets plus browser, SSH, AWS, Azure, and npm credentials.
Read More: https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html