ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command‑and‑control and a DPRK-linked crypto laundering network, turning a routine search click into a full-stack theft operation spanning browser, endpoint, blockchain, and exchange infrastructure. Instead of traditional web C2, the implant resolves its live command‑and‑control endpoints from Ethereum smart contracts, a takedown‑resistant pattern known as […]
Read the original article: