THREATOPS
THREAT OPSThreat News › DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

medthehackernewsPublished 2026-07-30

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.

The defining aspect of the attack is that bogus macOS software update screen stealthily

Attributed threat actors

MITRE ATT&CK techniques

Original source: https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html