North Korea Linked macOS Campaign Uses Fake Updates And ClickFix To Deploy Malware

North Korea Linked macOS Campaign Uses Fake Updates And ClickFix To Deploy Malware

Security researchers have identified a sophisticated macOS malvertising campaign linked to North Korean threat actors that uses fake software update screens to distribute cryptocurrency stealing malware. According to a report from AllSecure, the activity represents a new variation of the long running Contagious Interview campaign and introduces a different initial infection method while continuing to rely on advanced malware delivery techniques. Instead of beginning with fake job offers or developer recruitment messages commonly associated with previous campaigns, the latest attacks start when users click on a sponsored search result that redirects them to a malicious website impersonating a legitimate business.

Researchers explained that once the victim visits the malicious webpage, the browser immediately displays a convincing full screen macOS software update sequence that creates the appearance of a system restart or operating system update. During this process, the page secretly copies a malicious command to the system clipboard before instructing the user to open the Terminal application and paste the command manually. This social engineering technique, known as ClickFix, is designed to persuade users to execute malicious commands themselves. According to AllSecure, the experience is intentionally designed to create urgency by making users believe their computer has frozen or is rebooting unexpectedly. In the observed case, the victim had been searching online for electrophoresis machines before clicking on a sponsored search result for what appeared to be a legitimate supplier. The infection sequence reportedly began immediately after the fraudulent webpage loaded. Researchers also noted that the fake update process is intended to function only once, making it difficult to reproduce during subsequent attempts and increasing the likelihood that the attack will avoid casual investigation.

The copied Terminal command retrieves the next stage of the malware through a curl request, leading to the installation of a Node.js based backdoor configured to maintain persistence using a LaunchAgent. The malware then contacts command and control infrastructure using an EtherHiding technique, which retrieves the active server address from an Ethereum smart contract instead of relying on a fixed server location. Researchers stated that this blockchain based approach has previously been observed in earlier Contagious Interview campaigns linked to North Korean threat actors. Once active, the backdoor communicates with the command server every five minutes and executes JavaScript instructions received from the remote infrastructure. The malware subsequently downloads two additional payloads, including an information stealing program capable of collecting data from multiple web browsers, 157 cryptocurrency wallets, SSH credentials, AWS keys, Azure credentials, and npm authentication data. The second payload is a malicious browser extension disguised as Google Drive Offline that is installed by modifying Chrome Secure Preferences in order to steal cryptocurrency wallet assets.

AllSecure also identified two Ethereum smart contract addresses embedded within the malware that resolve the command and control servers identified as rg telemetry.sbs/api and th updates.sbs/analytics. According to the researchers, both smart contracts were deployed through a nearly identical process using temporary cryptocurrency wallets that were funded, configured, drained of remaining funds, and abandoned, suggesting an automated deployment strategy. Additional analysis found that both the Node.js backdoor and the malicious browser extension were financed through the same cryptocurrency wallet cluster, indicating they were operated by a single threat actor. Christian Papathanasiou, co founder and Chief Executive Officer of AllSecure, stated that while North Korean cyber campaigns are commonly associated with fake employment opportunities and software developer recruitment, this activity demonstrates that the same operational methods are now being applied to broader web browsing scenarios. The findings indicate that users searching for legitimate products or services may also become targets of advanced malware campaigns that combine social engineering, blockchain based infrastructure, and credential theft techniques to compromise macOS systems and cryptocurrency assets.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Post Comment