The Growing Threat of Malvertising on macOS
According to a report covered by The Hacker News, a North Korean-linked group has launched a new malvertising campaign that targets macOS users with fake software update screens to steal cryptocurrency. This attack is significant because it shows how threat actors are combining old tricks—like fake update warnings—with modern techniques to bypass security measures. Instead of relying on malicious downloads, the attackers trick users into running a harmful command themselves, making it harder for antivirus tools to detect.
What makes this campaign stand out is how it starts. Victims simply click on a sponsored search result for a legitimate-looking product, and then a full-screen fake macOS reboot screen appears. The page copies a dangerous command to the clipboard and urges the user to open Terminal and paste it. This social engineering preys on panic, as the computer appears frozen or broken. The attackers have also used blockchain-based command-and-control servers, which are extremely difficult to shut down.
Why This Attack Is Different and More Dangerous
Traditional cyber attacks often rely on email attachments or suspicious links. This campaign shows a shift toward search engine malvertising, where even a routine web search can lead to infection. For Australian businesses, this means the attack surface is widening. Employees searching for office equipment, lab supplies, or software could accidentally land on a malicious ad that looks completely normal.
The use of blockchain to host command-and-control addresses is another worrying development. By storing server addresses in Ethereum smart contracts, the attackers make their infrastructure resilient to takedowns. Even if one server is blocked, the malware can fetch a new address from the blockchain. This technique, sometimes called EtherHiding, adds a layer of complexity that most small and mid-sized businesses are not equipped to handle.
What This Means for Australian SMBs
Australian small and mid-sized businesses often run macOS devices alongside Windows machines. This campaign proves that Macs are not immune to sophisticated threats. The malware specifically targets cryptocurrency wallets—over 150 different types—and also steals browser credentials and cloud keys. Even if your business does not handle crypto, the information stealer can grab login details for AWS, Azure, and SSH keys, putting your entire cloud infrastructure at risk.
Because the attack begins with a simple web search, it can bypass many traditional email-based security filters. Employees who browse for work-related products are now potential targets. This means Australian SMBs must rethink their approach to endpoint security, especially for macOS devices, and consider browser-level protections like ad blockers and DNS filtering.
What You Can Do Now
- Train staff to recognise fake update screens and never paste unknown commands into Terminal or any command prompt. Legitimate software updates never require manual command-line actions.
- Deploy endpoint detection and response (EDR) tools on all macOS devices. Ensure they can monitor for suspicious clipboard activity and unauthorised Terminal commands.
- Use ad-blocking browser extensions and consider DNS-level filtering to block known malicious domains. This reduces the chance of employees clicking on sponsored malvertising links.
- Implement multi-factor authentication (MFA) on all cloud accounts and critical systems. Even if an attacker steals credentials, MFA can stop unauthorised access.
- Regularly review and restrict which browser extensions are allowed on company devices. The malware in this campaign sideloads a fake “Google Drive Offline” extension to drain wallets.
At MS&VG, we help Australian SMBs build practical cybersecurity defences tailored to their size and budget. From employee security awareness training to managed endpoint protection, our team can guide you through the latest threats and keep your business safe.