← Back to Feed

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

July 30, 2026 · The Hacker News · Severity: HIGH

This article describes a sophisticated macOS malvertising campaign attributed to North Korean threat actors, where users are redirected to fake web pages displaying a full-screen update sequence to deliver crypto-stealing malware. The attack is part of the ongoing Contagious Interview campaign.

Key Takeaways

  • North Korean hackers use macOS malvertising with fake updates.
  • Fake update pages deliver crypto-stealing malware to macOS users.
  • This campaign is a new iteration of Contagious Interview.
☕ Buy a Coffee