{"id":65359,"date":"2026-07-31T02:56:00","date_gmt":"2026-07-31T06:56:00","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=65359"},"modified":"2026-07-31T02:56:00","modified_gmt":"2026-07-31T06:56:00","slug":"dprk-macos-malvertising-clickfix","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/dprk-macos-malvertising-clickfix\/","title":{"rendered":"DPRK macOS Malvertising Drops Crypto-Stealing Malware via ClickFix"},"content":{"rendered":"<p>A sophisticated macOS malvertising campaign linked to North Korean threat actors has been deploying cryptocurrency-stealing malware through a deceptive <a href=\"https:\/\/overcentral.com\/en\/steam-clickfix-xmrig-attack\/\" title=\"Steam forum ClickFix attacks infect gamers with XMRig cryptominers\" data-iacss-internal=\"1\">ClickFix<\/a> technique that simulates a full-screen operating system update. The attack, identified as a new variant of the long-running Contagious Interview campaign, leverages blockchain-hosted command-and-control infrastructure to evade takedown and ultimately targets over 157 <a href=\"https:\/\/overcentral.com\/en\/ill-bloom-vulnerability-crypto-wallets\/\" title=\"&apos;Ill Bloom&apos; Flaw Drains $3.1 Million from Cryptocurrency Wallets\" data-iacss-internal=\"1\">cryptocurrency wallets<\/a> alongside browser credentials and cloud service keys. The campaign marks a significant evolution in the operational tactics of the Democratic People&rsquo;s Republic of Korea (DPRK) threat cluster, expanding beyond fake job interviews and coding assessments into broader web search scenarios.<\/p>\n<h2>The Attack Chain: From Sponsored Search Results to Full-Screen Deception<\/h2>\n<p>The infection sequence begins with a seemingly innocuous action: clicking on a sponsored search result. In the case analyzed by cybersecurity firm AllSecure, the victim was searching for electrophoresis machines and clicked on a paid advertisement for a company that appeared to sell them. Once the fake website loaded in the browser, however, the page immediately displayed a full-screen macOS reboot message, giving the impression that a software update was already underway. This visual trick is designed to induce panic by making the computer appear frozen or rebooting, prompting the user to follow instructions they would otherwise find suspicious.<\/p>\n<p>This delivery method represents a departure from typical Contagious Interview campaigns, which have historically relied on fake job offers, video assessments, or coding tests to lure targets. Instead, the attackers integrated the malvertising lure into organic search behavior, demonstrating an expanded threat model that exploits everyday browsing habits. The fake update page is also engineered to be single-use: any attempt to reproduce the sequence does not yield the same result, suggesting that the activation is tied to a unique session or cookie to hinder analysis.<\/p>\n<h3>How ClickFix Works in This Campaign<\/h3>\n<p>The key component of the attack is a well-known technique called ClickFix. While the fake macOS update sequence is displayed, the page stealthily copies a malicious command to the victim&rsquo;s clipboard. The page then prompts the user to open the Terminal app and paste the command. The command itself is a curl request designed to fetch the next-stage malware from a remote server. The psychological pressure of a frozen computer makes the victim more likely to comply without scrutinizing the pasted content.<\/p>\n<p>What is ClickFix? It is a social engineering method that tricks users into executing malicious code by making them believe they are fixing a system issue. In this campaign, the fake update screen induces urgency and panic, exploiting the user&rsquo;s trust in the operating system&rsquo;s update mechanism and their desire to restore normal function. The command is executed in the Terminal, which grants the malware full system access.<\/p>\n<h2>EtherHiding: Blockchain-Based Command-and-Control Evasion<\/h2>\n<p>The malvertising campaign is notable for its use of Ethereum smart contracts to store live command-and-control (C2) server addresses. This takedown-resistant approach, known as EtherHiding, has been previously employed by North Korean threat actors in the Contagious Interview cluster (also tracked as UNC5342). Instead of relying on traditional hosted domains that can be seized, the malware extracts the C2 address directly from an Ethereum contract. The Node.js backdoor deployed on the victim&rsquo;s system calls the contract periodically to resolve the current server endpoint.<\/p>\n<p>AllSecure&rsquo;s analysis identified two Ethereum addresses embedded in the malware, both acting as EtherHiding configuration contracts. These contracts returned the actual C2 domains used for communication: &ldquo;rg-telemetry.sbs\/api&rdquo; and &ldquo;th-updates.sbs\/analytics.&rdquo; The backdoor is configured to check in with the server every five minutes and execute any JavaScript code returned by it, enabling the attackers to maintain persistent remote access.<\/p>\n<h3>Industrialized Blockchain Deployment<\/h3>\n<p>The attackers appear to have automated the deployment of these contracts. AllSecure observed that each contract was created by a throwaway wallet using an identical four-step script: fund the wallet with approximately 0.0126 ETH, deploy the contract, write the configuration, forward the leftover approximately 0.006 ETH onward, and abandon the wallet. This pattern indicates an operator that has industrialized the deployment process&mdash;fund, deploy, configure, drain leftovers, abandon, and repeat. The consistency suggests a scripted workflow that allows rapid creation of new C2 infrastructure without manual intervention.<\/p>\n<h2>Two Final Payloads: A Cryptocurrency Stealer and a Chrome Extension Drainer<\/h2>\n<p>Once the Node.js backdoor establishes communication with the C2 server, it fetches two additional payloads. The first is an information stealer that harvests data from web browsers (including Chrome, Brave, Edge, Firefox, Opera, and Vivaldi), 157 cryptocurrency wallets, as well as SSH, AWS, Azure, and npm keys. The breadth of targeted wallets indicates a primary focus on cryptocurrency theft, but the inclusion of cloud and development credentials suggests a broader espionage or financial motive.<\/p>\n<p>The second payload is a malicious Chrome extension named &ldquo;<a href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Google<\/a> Drive Offline.&rdquo; This extension is sideloaded into the browser by patching Chrome&rsquo;s Secure Preferences file, a technique previously documented in other North Korean campaigns. Once installed, the extension is used to drain the victim&rsquo;s cryptocurrency wallets by intercepting transactions or directly extracting private keys. The extension&rsquo;s innocuous name helps it blend in among legitimate extensions, reducing suspicion.<\/p>\n<ul>\n<li><strong>Stealer payload:<\/strong> targets 157 cryptocurrency wallets across multiple chains, plus browser credentials, SSH keys, AWS\/Azure tokens, and npm registry keys.<\/li>\n<li><strong>Chrome extension (Google Drive Offline):<\/strong> sideloaded via Secure Preferences patching, used for wallet draining and ongoing surveillance.<\/li>\n<\/ul>\n<h2>Single Actor Behind the Campaign<\/h2>\n<p>Further analysis by AllSecure revealed that both the Node.js backdoor and the browser-extension drainer are funded from the same wallet cluster, strongly indicating that the entire operation is the work of a single actor. This consolidates the attribution to the DPRK-linked Contagious Interview group, which has consistently used EtherHiding and ClickFix techniques in prior attacks. The use of a unified funding source also suggests a centralized command structure capable of managing multiple payload development and deployment cycles.<\/p>\n<h2>Expanding the Threat Model: Beyond Fake Job Interviews<\/h2>\n<p>Christian Papathanasiou, co-founder and CEO of AllSecure, noted that DPRK-linked campaigns are often described through the lens of fake job interviews and developer recruitment, but this case shows the same operational logic appearing in a broader browsing scenario. &ldquo;That does not replace the fake-job pattern; it expands the threat model,&rdquo; Papathanasiou said. The campaign demonstrates that North Korean threat actors are diversifying their initial access vectors, moving beyond targeted individual recruitment to mass malvertising that can ensnare anyone who clicks on a sponsored link.<\/p>\n<p>The attack is significant not only for its technical sophistication&mdash;combining ClickFix, EtherHiding, and multi-stage payloads&mdash;but for its psychological and practical implications. The fake macOS update screen is designed to induce panic and override the user&rsquo;s usual caution. The single-use nature of the lure complicates detection and analysis by security researchers. And the blockchain-based C2 infrastructure makes standard takedown procedures ineffective, as the contract can be updated with new server addresses without the attackers needing to maintain a static domain.<\/p>\n<h3>What Makes This Campaign Different from Previous Contagious Interview Attacks?<\/h3>\n<p>Earlier Contagious Interview campaigns typically began with a direct message or email offering a job interview, a coding test, or a video assessment. Targets were often developers or engineers in cryptocurrency-related businesses. In contrast, this campaign starts with a standard web search and a sponsored result, lowering the barrier to infection. The attackers are essentially casting a wider net, using search engine ads to reach users who may have no connection to the cryptocurrency industry but are simply searching for equipment or services. Once the victim clicks the ad, the technical infection chain is identical to previous attacks, but the initial lure is far more generic.<\/p>\n<p>This shift is notable because it implies that the threat actor has access to advertising infrastructure and is willing to pay for sponsored results to distribute malware. The use of search engine malvertising (malicious advertising) is a well-known tactic, but its combination with a fake macOS update and blockchain C2 is relatively novel. The campaign also highlights the growing overlap between financially motivated cybercrime and state-sponsored espionage: the stolen cryptocurrency wallets provide immediate financial gain, while the stolen cloud and SSH keys could be used for further intrusions.<\/p>\n<h2>Implications for macOS Users and Organizations<\/h2>\n<p>For macOS users, this campaign underscores the importance of being cautious about any unexpected full-screen prompts that ask them to open Terminal and paste commands. Legitimate software updates do not include such instructions. The ClickFix technique relies on the user&rsquo;s willingness to type a command without understanding what it does. Organizations with macOS fleets should implement policies that restrict Terminal access for non-privileged users and train employees to recognize these social engineering tactics.<\/p>\n<p>Furthermore, the use of Ethereum smart contracts for C2 communication presents a challenge for network defenders. Traditional domain-based blocklists are ineffective because the contract can return different IP addresses over time without changing the contract itself. Monitoring for unusual outbound connections to smart contract RPC endpoints or to the specific domains observed (rg-telemetry.sbs, th-updates.sbs) can help detect infections. However, because the attackers can quickly create new contracts and wallets, automated detection requires broader behavioral indicators.<\/p>\n<h2>Future Outlook: The Industrialization of DPRK Malware Operations<\/h2>\n<p>The pattern of throwaway wallets and scripted contract deployment suggests that the Contagious Interview group has invested in tooling to scale its operations. This industrialization means that takedowns of individual contracts or domains will have minimal impact; the attackers can rapidly create replacements. Security researchers and law enforcement agencies may need to target the funding sources or the advertising accounts used for malvertising to disrupt the campaign at a higher level.<\/p>\n<p>As North Korean threat actors continue to refine their techniques, the line between targeted attacks and mass malware distribution will blur. The success of this macOS malvertising campaign may encourage similar efforts targeting <a href=\"https:\/\/overcentral.com\/en\/secure-boot-key-update-deadline\/\" title=\"Secure Boot Key Update Deadline Nears for Windows and Linux Users\" data-iacss-internal=\"1\">Windows and Linux users<\/a>, using the same ClickFix and EtherHiding playbook. The cryptocurrency ecosystem, with its pseudonymous nature and high value, remains an attractive target for DPRK-linked groups that use stolen funds to bypass international sanctions. The broader threat model now includes any user who searches for commercial products online and clicks on a sponsored result, without needing to be a developer or cryptocurrency investor.<\/p>\n<p>In the end, this campaign is a reminder that sophisticated state-sponsored adversaries are continuously adapting their tactics to exploit human psychology and technological weaknesses. The combination of malvertising, fake updates, clipboard hijacking, and blockchain C2 represents a mature operational capability that will likely persist and evolve. Defenders must anticipate that the next iteration could target other operating systems, use different social engineering pretexts, or incorporate even more resilient infrastructure. The Contagious Interview campaign may have started with fake job interviews, but it has clearly grown into a multifaceted threat that demands a proportional and equally adaptive response.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A sophisticated macOS malvertising campaign linked to North Korean threat actors has been deploying cryptocurrency-stealing malware through a deceptive ClickFix technique that simulates a full-screen operating system update. The attack, identified as a new variant of the long-running Contagious Interview campaign, leverages blockchain-hosted command-and-control infrastructure to evade takedown and ultimately targets over 157 cryptocurrency wallets [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84198,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/65359.png","fifu_image_alt":"DPRK macOS Malvertising Drops Crypto-Stealing Malware via ClickFix","footnotes":""},"categories":[349],"tags":[],"class_list":["post-65359","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/65359.png","fifu_image_alt":"DPRK macOS Malvertising Drops Crypto-Stealing Malware via ClickFix","fifu_redirection_url":"https:\/\/crypto.news\/infini-exploiter-resurfaces-to-buy-eth-dip\/","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/65359","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=65359"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/65359\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84198"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=65359"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=65359"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=65359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}