news.mlab.sh
Back to the feed
threat-intel

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

High
Image: The Hacker News
Summary

North Korean-linked threat actors are using a sophisticated macOS malvertising campaign to deliver crypto-stealing malware. The campaign mimics a fake software update sequence to trick users into executing a malicious command via the Terminal app, ultimately installing a Node.js backdoor that harvests cryptocurrency wallet data and a Chrome extension for wallet draining. This tactic, known as EtherHiding, utilizes blockchain-hosted command and control to evade detection.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.