- North Korean hackers are using a fake macOS update screen to trick users into running malicious Terminal commands.
- The campaign employs blockchain-hosted command-and-control (C2) via Ethereum smart contracts, a technique known as EtherHiding.
- The malware targets 157 cryptocurrency wallets and deploys a malicious Chrome extension to drain funds.
- The attack begins with a seemingly harmless web search, not a fake job offer.
Cybersecurity researchers at AllSecure have uncovered a sophisticated macOS malvertising campaign, attributed to North Korean threat actors, that uses a fake full-screen macOS update to deliver malware. The attack begins when a user clicks a sponsored search result for companies like those selling electrophoresis machines, immediately displaying a bogus reboot sequence that is designed to “induce panic.”
The fake page stealthily copies a curl command to the clipboard and prompts the victim to open Terminal and paste it, a technique known as ClickFix. Consequently, the command executes a Node.js backdoor that uses a LaunchAgent for persistence and calls an Ethereum smart contract to resolve the live C2 server address, which AllSecure detailed. This takedown-resistant approach, called EtherHiding, polls the server every five minutes to execute JavaScript code.
The implant fetches two payloads: an information stealer capable of harvesting data from browsers and 157 cryptocurrency wallets, and a malicious “Google Drive Offline” extension that patches Chrome’s Secure Preferences file. The activity is funded from a single wallet cluster, revealing a single actor with an operational pattern described as “fund, deploy, configure, drain leftovers, abandon, repeat.”
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
