threat-intel
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
High
Summary
North Korean-linked threat actors are using a sophisticated macOS malvertising campaign to deliver crypto-stealing malware. The campaign mimics a fake software update sequence to trick users into executing a malicious command via the Terminal app, ultimately installing a Node.js backdoor that harvests cryptocurrency wallet data and a Chrome extension for wallet draining. This tactic, known as EtherHiding, utilizes blockchain-hosted command and control to evade detection.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
