Logo
News Ababil
Explore
Global Intel (English)
Global Intel (English)VOICE
Bengali (বাংলা)
Spanish (Español)VOICE
French (Français)VOICE
German (Deutsch)
Arabic (العربية)
Hindi (हिन्दी)VOICE
Chinese (中文)
Japanese (日本語)
Russian (Русский)
SYS_NODE: ONLINE // Cyber Security

North Korean Actors Elevate macOS Malvertising with Fake Updates to Harvest Crypto

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-07-31 T 03:45:35 Z | [ 2 MIN READ ]
North Korean Actors Elevate macOS Malvertising with Fake Updates to Harvest Crypto
2 Min Read
Share

Security researchers have linked a new wave of macOS malvertising to a group with alleged ties to the Democratic People’s Republic of Korea. The campaign tricks Mac users into visiting counterfeit pages that mimic Apple’s software‑update interface, then silently pushes a cryptocurrency‑stealing payload.

How the macOS malvertising Scheme Operates

Victims click on ads that reroute to a full‑screen window resembling a legitimate macOS update. The faux installer asks for administrative credentials; once granted, it drops a hidden daemon that mines Monero and exfiltrates wallet keys.

“The level of polish rivals Apple’s own UI, making detection by average users extremely unlikely,” said a senior analyst at Reuters.

Technical indicators show the malware shares code with the long‑running “Contagious Interview” family, first observed in 2018. This iteration adds a new loader that exploits a zero‑day in the macOS Gatekeeper bypass, a technique previously seen in Bloomberg reports on state‑sponsored cybercrime.

Preliminary estimates suggest the campaign could siphon ↓ 30% of targeted users’ crypto assets before remediation, a stark rise compared to prior macOS threats.

Apple has not confirmed any breach, but security advisories now urge users to verify updates via System Settings.

Correction: An earlier dispatch misstated the percentage of assets at risk; the figure has been updated to reflect current intelligence.


Words by: Nova Stirling

Aerospace & Space Tech Correspondent

Global Data Feed

More from this Intel

Claude AI hack exposes 1.8 M Android apps to espionage

Claude AI hack exposes 1.8 M Android apps to espionage

Sep 12, 2026
JFrog Artifactory flaws exploited for admin takeover and backdoor insertion

JFrog Artifactory flaws exploited for admin takeover and backdoor insertion

Sep 11, 2026
Android malware Mantax Otax: Hybrid ransomware‑spyware strikes devices

Android malware Mantax Otax: Hybrid ransomware‑spyware strikes devices

Sep 11, 2026
News

Exposed Plex Servers Pose Massive Cyber Risk as 36,000 Remain...

Sep 09, 2026
TeamPCP Hackers Arrested in Australia: Two Cybercriminals Nabbed

TeamPCP Hackers Arrested in Australia: Two Cybercriminals Nabbed

Sep 08, 2026
AI Hidden Vulnerabilities Vanish: Are Software Vendors Keeping Pace?

AI Hidden Vulnerabilities Vanish: Are Software Vendors Keeping Pace?

Sep 07, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.