Bottom Line: North Korea-linked actors are using fake macOS update screens to deliver malware in the Contagious Interview campaign.
Threat actors with connections to North Korea are conducting a malvertising campaign that redirects users to fake pages featuring full-screen macOS update sequences to deliver malware. The campaign is part of a new iteration of the long-running Contagious Interview operation.
North Korea-linked threat actors have conducted a macOS malvertising campaign that leverages fake software update screens to compromise systems. The campaign is classified as a new phase of the known Contagious Interview operation and aims to trick users into downloading malware through deceptively realistic macOS update sequences.
The central feature of the attack is that bogus macOS update screens inconspicuously inject malware while presenting users with a complete, non-existent update routine. This approach combines social engineering with technical deception to circumvent the warning and detection thresholds of users and security solutions.
For CISOs, this campaign represents an increased risk to macOS endpoint security. The exploitation of trusted UI elements (system updates) as an attack vehicle demonstrates that user awareness training must increasingly focus on validating update sources. At the same time, EDR solutions and browser security should be configured to detect and block suspicious redirects and inauthentic update prompts.
Source: thehackernews.com · Published July 30, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.