🟠 High | Source: The Hacker News
North Korean threat actors have launched a sophisticated macOS malvertising campaign that tricks users into viewing a convincing fake system update screen, then silently installs cryptocurrency-stealing malware. This is a new iteration of the ‘Contagious Interview’ campaign, a long-running DPRK operation targeting crypto assets. The attack is particularly dangerous because the full-screen fake update sequence is highly convincing and bypasses typical user suspicion.
Security Architect’s Take: Ensure endpoint security tooling on macOS devices enforces application allowlisting and blocks unsigned or unnotarised binaries, particularly those downloaded outside of the Mac App Store. Consider pushing browser-level ad-blocking and malicious URL filtering policies to all managed macOS endpoints, and brief development and security teams — who are frequent targets of Contagious Interview — on social engineering indicators.
Original advisory: DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware