TechNewsReel
Live

North Korean Actors Use macOS Malvertising to Drain Crypto Wallets

Threat actors linked to the 'Contagious Interview' campaign are using fake security updates to trick Mac users into installing crypto-stealing malware.

TechNewsReel Newsroom · August 2, 2026

North Korean threat actors are leveraging a sophisticated macOS malvertising scheme to deploy cryptocurrency-stealing malware. The campaign marks a strategic shift in delivery methods, moving from targeted professional lures to broad-reach sponsored search results to compromise high-value targets.

According to reports from The Hacker News and Daily Security Review, the attackers utilize a social engineering tactic known as "ClickFix." Victims are lured via sponsored ads to a fake, full-screen macOS update page claiming a "Critical Security Update Required." The site automatically copies a malicious curl command to the user's clipboard and prompts them to paste it directly into the macOS Terminal app. Once executed, this command installs a Node.js backdoor that serves as a gateway for subsequent payloads.

Evolution of the Threat

This activity is attributed to UNC5342, the group behind the "Contagious Interview" campaign. Historically, this actor targeted software developers through fabricated job opportunities to gain access to corporate networks. However, this new iteration expands the threat model by using general malvertising—such as ads for electrophoresis machines—to target a wider audience of cryptocurrency holders and cloud infrastructure administrators.

Christian Papathanasiou, co-founder and CEO of AllSecure, noted that the operational logic of the group is now appearing in broader browsing scenarios, suggesting that the malvertising approach expands the threat model rather than replacing the previous fake-job pattern.

Technical Sophistication

The campaign deploys two primary payloads. The first is an information stealer designed to harvest cloud keys—including AWS, Azure, npm, and SSH—and target cryptocurrency wallets. The second is a sideloaded Chrome extension disguised as "Google Drive Offline," which functions as a wallet drainer.

To ensure the operation remains resilient against takedowns, the malware employs a technique called "EtherHiding." This method involves extracting command-and-control (C2) addresses and payloads from Ethereum and BNB Smart Chain smart contracts. By hosting infrastructure data on the blockchain, the actors make it significantly harder for security researchers to disrupt the communication chain through traditional domain or IP blocking.

Industry Implications

This pivot represents a "mainstreaming" of DPRK delivery tactics. By combining the accessibility of malvertising with the psychological pressure of a fake security alert, the actors can compromise cloud admins and crypto investors without needing a specific professional pretext. Furthermore, the use of browser-extension-based drainers and blockchain-hosted C2s allows the malware to bypass many traditional OS-level antivirus scanners.

Security teams are advised to monitor for unauthorized Terminal activity and suspicious Chrome extensions. As the group continues to iterate on its delivery mechanisms, the industry must watch for further shifts in how these actors leverage decentralized infrastructure to maintain persistence.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.