CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3563

As cited

Copy frozen at (site build).

threat intel

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

North Korean-linked threat actors conducted a macOS malvertising campaign impersonating software updates to distribute cryptocurrency-stealing malware. The attack, part of the Contagious Interview campaign, directs users to fake update screens designed to deliver the malicious payload.

Why it matters: macOS users and cryptocurrency holders face credential and asset theft; practitioners should educate users on verifying update sources directly through System Preferences and monitor for suspicious redirects in web traffic.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

North Korean-linked threat actors conducted a macOS malvertising campaign impersonating software updates to distribute cryptocurrency-stealing malware. The attack, part of the Contagious Interview campaign, directs users to fake update screens designed to deliver the malicious payload.

Why it matters: macOS users and cryptocurrency holders face credential and asset theft; practitioners should educate users on verifying update sources directly through System Preferences and monitor for suspicious redirects in web traffic.

VendorsApple
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary