HackMyIP
← Back to News
2026-07-30 The Hacker News

DPRK Hackers Use Fake macOS Updates to Steal Crypto via EtherHiding

MalwareAPTThreat Intel

North Korean-linked threat actors have been tied to a sophisticated macOS malvertising campaign that abuses fake software update screens to deliver cryptocurrency-stealing malware as part of a new iteration of the long-running Contagious Interview operation. According to research from AllSecure shared with The Hacker News, the campaign—tracked as UNC5342—redirects victims searching for everyday products to attacker-controlled pages that display a full-screen, non-existent macOS update sequence. The defining trick is a known technique called ClickFix: the malicious page silently copies an attack command to the victim's clipboard and then instructs the user to open Terminal and paste it, exploiting panic induced by a frozen-looking system. Once executed, the curl command retrieves a next-stage payload that installs a Node.js backdoor and a LaunchAgent for persistence.

The infection chain is a notable departure from previous Contagious Interview lures, which typically relied on fake job offers, coding assessments, or video interviews. In this case, the entry point was a sponsored search result for an unrelated target—researchers observed one victim searching for electrophoresis machines and clicking a poisoned ad. From the moment the fake page loaded, a single-use activation sequence began, with the fake update screen giving way to a clipboard-paste prompt in Terminal. Researchers noted that attempting to replay the sequence does not reproduce the attack, indicating deliberate one-time targeting. The lure itself may look innocuous, which is why users should verify unfamiliar domains with a WHOIS lookup before clicking sponsored results.

For command-and-control, the operators leaned on EtherHiding, a takedown-resistant approach that pulls the live C2 address from an Ethereum smart contract rather than a hardcoded domain. The Node.js implant polls this contract, resolves the server, and fetches two additional payloads every five minutes: an information stealer capable of targeting 157 cryptocurrency wallet extensions and a malicious Chrome extension designed to siphon credentials and session data. Because the C2 lives on-chain, traditional DNS leak test and blocklist defenses are far less effective against this infrastructure. Users concerned about exposure can run a privacy checkup to review browser extensions, installed LaunchAgents, and outbound connections that may betray a compromised host.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →