North Korean-linked threat actors have launched a macOS malvertising campaign that redirects users to fake software update screens to deploy crypto-stealing malware. The attack represents a new phase of the Contagious Interview campaign, a long-running operation tied to DPRK threat groups.

The malvertising scheme works by directing victims to fraudulent web pages that display full-screen fake macOS update sequences. These counterfeit update screens appear legitimate enough to trick users into executing malicious code. The malware ultimately targets cryptocurrency wallets and digital assets stored on compromised systems.

Contagious Interview operators have previously targeted cryptocurrency exchanges and blockchain platforms. This latest iteration refines their delivery mechanism by leveraging browser-based malvertising rather than traditional spear-phishing or watering hole attacks. The fake update interface eliminates a critical barrier to infection, as users expect macOS to prompt updates regularly.

The campaign exploits user psychology and trust in system-level update procedures. When users encounter what appears to be an official Apple update notification, they typically proceed without skepticism. The full-screen overlay design further reinforces legitimacy by mimicking native macOS interface elements.

Organizations and individuals handling cryptocurrency should treat unsolicited update prompts with caution. Legitimate macOS updates route through System Preferences or the App Store and never require users to visit external websites. Visiting suspicious ad links remains the primary infection vector.

Security researchers attribute the operation to North Korean state-sponsored actors based on infrastructure analysis, timing patterns, and campaign overlaps with known DPRK groups. The Contagious Interview framework has maintained operational continuity across multiple years, suggesting consistent resource allocation and strategic focus on cryptocurrency theft.

Users should verify update authenticity by checking System Preferences directly rather than clicking update notifications from web pages. Security teams should monitor for redirects to suspicious domains and block known malvertising infrastructure.