


Perceptive Security
SOC/SIEM Consultancy

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Published:
30 juli 2026 om 18:18:24
Alert date:
30 juli 2026 om 20:07:35
Source:
thehackernews.com
Ransomware & Malware, Operating Systems
North Korea-linked threat actors have been attributed to a sophisticated macOS malvertising campaign targeting cryptocurrency users. The attack is part of a new iteration of the long-running Contagious Interview campaign. Users are redirected to fake web pages that display a full-screen, convincing but non-existent macOS software update sequence. This social engineering technique is used to trick users into executing malware under the guise of a legitimate system update. The campaign is designed to deliver crypto-stealing malware to victims. The use of malvertising as an initial access vector indicates a broad targeting approach. The campaign demonstrates continued evolution in North Korean threat actor tactics targeting macOS users and the cryptocurrency sector.
Technical details
Mitigation steps:
Affected products:
macOS
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
