Sponsored Mac update pages hide North Korean wallet drainer

North Korean hackers disguise clipboard malware as fake macOS update screens in a new malvertising campaign.

AppleThreat Staff
2 Min Read

If your Mac suddenly shows a system update screen, then asks you to open Terminal and paste a command, you are likely staring at a trap built by North Korean hackers. Security firm AllSecure documented a campaign that turns sponsored search ads into fake update pages engineered to steal cryptocurrency.

The attack plays on urgency. A page that appears to be a reboot sequence makes the machine look frozen, and the message that follows instructs the user to copy a command and run it in Terminal. AllSecure says victims who believe their operating system is failing are far more likely to comply.

Researchers observed one victim who searched for electrophoresis machines and clicked what looked like a supplier’s promoted result. The pages worked once only, with the same sequence never repeating on a second visit.

The pasted command pulls in a Node.js backdoor that keeps itself alive through a LaunchAgent. Its command-and-control setup is unusual: the server address comes from a smart contract on the Ethereum blockchain, a trick called EtherHiding that complicates takedown efforts.

Every five minutes the implant dials its controller and executes whatever JavaScript comes back. One stealer payload harvests browser profiles, SSH and cloud credentials, and login data for 157 cryptocurrency wallets. Another, a fake Google Drive Offline extension, edits the browser’s Secure Preferences file to gain wallet-draining access.

The campaign builds on the Contagious Interview operation, previously known for fake developer job offers. AllSecure CEO Christian Papathanasiou says the group now targets ordinary browsing instead of waiting for victims to apply for fictitious jobs. The Ethereum contracts follow an identical four-step deployment script, suggesting industrialized infrastructure.

The lesson for Mac users is simple. Genuine Apple updates never ask for terminal commands. Any web page that requests pasting code into Terminal should be closed immediately.

Share This Article