The record
Written from the 1 report below. Nothing here is unsourced.
- North Korean-linked hackers are running a malvertising campaign against macOS users through a new twist in their long-running Contagious Interview operation.
- Victims clicking on sponsored search results are shown a fake full-screen macOS update page that copies a malicious command to the clipboard and tricks them into running it in the Terminal app.
- This installs a backdoor that fetches an information stealer targeting 157 cryptocurrency wallets, browser data, and cloud credentials, along with a Chrome extension used to drain crypto wallets.
- The campaign uses blockchain-based servers to resist takedowns, showing the group is expanding beyond its usual fake job offer lures to ordinary web browsing.
What to watch next
- Whether the malvertising lure spreads to more search terms and target companies
- Tracking of the Ethereum wallet cluster funding the contracts for further campaigns
- Potential takedowns or blocking of the C2 domains rg-telemetry.sbs and th-updates.sbs
Coverage1
1 report
English national1
All filed from India
Named North Korea · Chrome · macOS · AllSecure · Christian Papathanasiou · Ethereum
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
