A sophisticated cyberattack orchestrated by North Korea targets cryptocurrency wallets, browser data, and developer credentials through deceptive macOS update screens designed to trick victims into installing malware. The malware also installed an infostealer that searches for wallet data from 157 cryptocurrency wallets, including saved passwords, cookies, history, bookmarks, SSH keys, cloud credentials, npm configuration files, and Foundry keystores potentially revealing development environments. Stolen cloud keys, source-control credentials, and browser sessions provide attackers with a pathway into corporate networks, similar to North Korean npm package attacks that targeted developers and sensitive project data.
Indicators of Compromise (IoCs): Type Indicator Description SHA-256 529815d365a8ec8da165f3993ada3ad452381b56c736cd25cdf328968b4ab795 Node.js Remote Access Trojan (RAT) v1.0.3 SHA-256 7eca7aef8dcc46f15349509ac3dff8c0a71295c233787872c3842e058f9d7c50 Infostealer module SHA-256 370a5ae7f91291559ce514f44c50430dd2c35ed866bedcf6ac5f4f896259fbed Malicious Chrome MV3 extension Domain real-tumble.pro Stage 0 delivery domain URL https://rg-telemetry.sbs/api Backdoor C2 URL https://th-updates.sbs/analytics Extension C2 URL https://eth-mainnet.rpcfast.com/?apikey=xbhWBI1Wkguk8SNMu1bvvLurPGLXmgwYeC4S6g2H7WdwFigZSmPWVZRxrskEQwIf Hardcoded operator RPC API endpoint Ethereum contract 0x2acA749b59529f5CBCd6fbd34B35b1A546713dF6 EtherHiding contract for backdoor configuration Ethereum contract 0x85a6d913aaC80286f01Fa082ef0B96C188673043 EtherHiding contract for extension configuration Contract selector 0x3bc5de30 Smart-contract getter selector XOR keys 9f10d0899beff7952f586a49305f8b14, 2752df77aeb348657f5fb59a22d65f4a C2 traffic XOR keys Extension name Google Drive Offline Malicious MV3 browser extension disguise Ethereum wallets 0x277765FB63601cE5A9814daf68aA2A57F54eA968, 0x89c5151236De544d077fC69813A4db89224EE8A1 Attacker funder wallets Ethereum wallets 0xdf16a4d0a234a2bbc4d21645d4c7a19d2db8f192, 0x75ac1ebf164c6f2ac24e73bb4c9518b8d93559e2 Attacker treasury hubs Persistence artifacts ~/Library/LaunchAgents/com.











