← BACK TO FEED
TAG

etherhiding1 article

North Korea's Contagious Interview Campaign Goes Full ClickFix With Blockchain C2

North Korea-linked threat actors have launched a sophisticated macOS malvertising campaign, dubbed a new iteration of "Contagious Interview," that redirects users to fake websites displaying a convincing full-screen fake software update to trick them into running malicious Terminal commands via the ClickFix technique. The malware uses "EtherHiding" — embedding C2 server addresses in Ethereum smart contracts — to resist takedowns, ultimately delivering an information stealer targeting 157 cryptocurrency wallets and a malicious Chrome extension designed to drain victims' funds. Notably, this campaign departs from the group's typical fake job interview lures, instead targeting ordinary web searches, suggesting North Korean operators are broadening their attack vectors beyond developer recruitment scenarios.

31 Jul 2026