Trojanized Mac installers are posing as The Unarchiver and other popular apps: Header image
Emerging Threats 9 min read

Trojanized Mac installers are posing as The Unarchiver and other popular apps

Published:Sep 10, 2026

North Korean hackers are back, targeting Mac users with fake malicious apps. These apps, linked to the Contagious Interview threat campaign, breach your Mac with the OtterCookie infostealer if installed.

North Korean “Contagious Interview” hackers pose as fake recruiters and lure their targets with promises of employment. The jobs, however, are fake. This new report links lure websites targeting Web3 and blockchain developers, accounting professionals, and other sectors. Here’s what you need to know and how to keep safe.  

Jamf Threat Labs recently reported that 14 fake and malicious Mac apps were found to be trojan malware coded to breach your Mac and install the OtterCookie infostealer. 

Screenshot shared by Jamf Threat Labs showing a fake Mac app from this campaign.
A screenshot shared by Jamf Threat Labs shows a fake Mac app from this campaign. Image: Screenshot, Moonlock.

According to the reports, these fake Mac apps share similarities with recent North Korean threat campaigns, specifically ones linked to the Contagious Interview group. The impersonated apps include: The Unarchiver, Presentify, PDFify, Magic Disk Cleaner, Sketch2026.2, SiteSucker Pro, RAR Extractor Max, Mp3tag, Mole, HextEdit, Folder Preview Pro, Disk Doctor Pro, ServerCat, and Bartender.

article snippet with Moonlock logo

Stop OtterCookie and other stealers

Moonlock keeps an eye on your Mac 24/7, blocking malware threats like infostealers, backdoors, and trojans before they can do damage.
try 7 days free

Jamf said this threat campaign is in early testing and development stages. Nevertheless, if you recently downloaded these apps on your Mac from an untrusted, unverified source, or someone told you to download them, you should probably run a malware scan. 

To breach Mac computers, Contagious Interview has used several attack chains and techniques. These have included fake Zoom updates that contain malware. More recently, they have used increasingly complex techniques like hiding malware inside developers’ tests. Jamf Threat Labs said these new, fake trojanized Mac apps share the same staging infrastructure as recent North Korean “coding tests” presented by fake recruiters.

Malicious DMGs and PKGs posing as macOS apps

The fake Mac apps in this campaign were first discovered on VirusTotal, a popular website among cybersecurity researchers that scans and analyzes malware samples, IPs, and online sites. Checking some of the information on these apps on VirusTotal, we found that the earliest scans on 2 of these malicious apps date back to July of this year. 

All 14 fake apps come in two file formats, DMGs and PKGs. The .dmg software package format is primarily used by macOS to install applications and updates. The .pkg file format is an Apple Disk Image used by macOS to distribute and install software. 

All the files analyzed by Jamf were unsigned by a developer. When an app has no developer ID signature, your Mac’s built-in security feature, Gatekeeper, will automatically block the install. It will then warn you that the file may be dangerous and could contain malware. 

Jamf said that to open and install these apps, the com.apple.quarantine security feature must be removed. Users can remove the Apple Quarantine attribute from apps they trust by using a simple line of code that runs in your Mac Terminal. This is common, for example, in the developer world. When developers work with unreleased apps that are being tested, Gatekeeper flags them because they are not yet notarized or signed with a developer ID.

Jamf Threat Labs shared a screenshot of Gatekeeper blocking and flagging one of these fake Mac apps.
Jamf Threat Labs shared a screenshot of Gatekeeper blocking and flagging one of these fake Mac apps. Image: Screenshot, Moonlock.

However, it is also common for cybercriminals and threat groups to include instructions to bypass Gatekeeper when distributing malicious apps. The cybercriminals’ instructions are designed to trick you into allowing untrusted, unnotarized, and unsigned apps to be installed.

Bottom line: If someone sends you a Mac app and a set of step-by-step instructions on how to install it, be on your guard. You must be 100% certain you can trust the app before you install it. 

What happens when you install these fake apps on your Mac

As previously mentioned, installing these fake Mac apps on your computer requires that the user manually remove the Quarantine. If you get past that stage and still continue the install, what you will see on your screen is the app you downloaded opening. Business as usual. However, more is happening in the background.

Using a curl command, your Mac connects to malicious infrastructure (hxxp://162.0.239[.]89), fetching stages and payloads. Then, at Stage 4, the infostealer OtterCookie breaches your Mac.

Jamf Threat Labs screenshot shows how a Mac monitoring tool reveals malicious background processes when installing a fake Mac app.
Jamf Threat Labs’ screenshot shows how a Mac monitoring tool reveals malicious background processes when installing a fake Mac app. Image: Screenshot, Moonlock.

All this happens in the background without you noticing it. Unless you are looking for suspicious behavior using a Mac monitoring tool that allows you to visualize these background processes, as Jamf shows in the screenshot above, there will be no indication that this is going on.

OtterCookie is not your usual Mac stealer. It goes above and beyond.

OtterCookie has been around for years and has been actively updated. In 2025, OtterCookie emerged in its fourth version, with capabilities to breach Windows, macOS, and Linux environments.

Back then, it was also used in a Contagious Interview campaign. That version of OtterCookie could steal content from clipboards, access macOS files, and detect virtual machines (which cybersecurity researchers use to study malware in isolated environments). It could also collect documents, image files, and data and files related to cryptocurrency. Plus, it could also establish a C2 communication channel with attacker-controlled infrastructure to extract data and receive commands.

OtterCookie in its fourth version could breach the Google Chrome browser, stealing usernames and passwords. It could also steal data and files linked to MetaMask, the Brave browser, and macOS credentials.

In March 2026, OtterCookie got another update. This update focused on integrating a more resilient and robust communication channel and a backdoor to exfiltrate data and execute remote commands on your Mac. The backdoor was observed beaconing to the attacker’s controlled infrastructure at periodic intervals. In this way, it acted much like nation-state spyware, not just a smash-and-grab stealer.

The OtterCookie backdoor was coded to establish persistence and remain hidden deep inside your macOS. It was also capable of going after your files, wallet mnemonic phrases, password manager data from KeePass Password Safe databases, 1Password artifacts, Notes, Cryptographic keys, user and system data, and developer environment data. 

Jamf said that the version of OtterCookie used in this new set of fake Mac apps can do similar things. This includes installing a remote access trojan, stealing browser and crypto data, scanning the in-memory file system for specific file extensions and sensitive files, and accessing the clipboard clipper to steal clipboard data. 

New websites linked to Contagious Interview appear to lure users from Web3, blockchain, and finance and accounting 

VirusTotal data shows that the IP 162.0.239[.]85, where the malware was hosted in this campaign, links to several websites. These websites appear to be classic Contagious Interview online lures. 

The W3PI new token and BEP-20 protocol site linked to Contagious Interview was still live when this report was being written.
The W3PI new token and BEP-20 protocol site linked to Contagious Interview was still live when this report was being written. Image: Screenshot, Moonlock.

The sites include w3pi[.]social, miniapp.w3pi[.]social, softcus[.]net, pobelstudio[.]com, pobel[.]studio, kikaiverse[.]com, and lalitae[.]com. 

Of these sites, only 2 appeared online and were active when we checked them. One, w3pi[.]social, is notable. The site looks like an authentic new blockchain protocol site where community projects and bounties are offered in exchange for rewards, and fake giveaways appear to lure users from the Web3 and blockchain community.

One of the sites linked to this campaign, still active when this report was being written.
One of the sites linked to this campaign, still active when this report was being written. Image: Screenshot, Moonlock.

The w3pi[.]social BEP-20 token protocol does not seem to be operational in terms of actual transactions showing on the blockchain. But the site includes a WhitePaper and a GitHub organization page with resources, much like any new BEP-20 contract token would.

A nation-state threat actor developing a new BEP-20 contract token, whether it is a real new token or a non-functional website, is something that stands out dramatically. Not only is this something new and different. It also stands out for its potential for damage and possible use cases.

Clicking on the "bounty map" on the fake W3PI new blockchain token and protocol, opens up this Telegram channel.
Clicking on the “bounty map” on the fake W3PI new blockchain token and protocol opens this Telegram channel. Image: Screenshot, Moonlock.

The other active site we checked, softcus[.]net, shows an online accounting and finance management platform in Spanish claiming to be a fiscal platform specifically for the Central American country of El Salvador. This site could be luring users in El Salvador or the broader Latin America and Caribbean region, as well as other users who speak Spanish and work in finance and accounting. 

Another site linked to this Contagious Interview campaign is in Spanish and offers a fiscal platform for the country of El Salvador.
Another site linked to this Contagious Interview campaign is in Spanish. It offers a fiscal platform for the country of El Salvador. Image: Screenshot, Moonlock.

How to keep safe from the OtterCookie malware

All this may sound worrying. However, there are a couple of solid tips that can help you significantly reduce the risks of Contagious Interview campaigns that have been running for years. 

Get Moonlock. It will flag OtterCookie and other malware. 

The Moonlock antivirus app is constantly updated to deal with new Mac malware and threats, including malware from Contagious Interview campaigns.

Once you download and install the Moonlock app, Real-Time Protection will run in the background. The feature checks everything you interact with for threats and suspicious behavior. This includes emails, online files, and even terminal commands (for ClickFix threats that use that path). 

Screenshot of the the Moonlock app user interface.
The Moonlock app. Image: Screenshot, Moonlock.

Additionally, the Moonlock app builds up your security through multiple layers. Its built-in VPN is designed for safe and private browsing. Meanwhile, the Security Advisor can help you build safe digital habits that withstand the testing of social engineering and new cyberattacks. 

Screenshot of Moonlock, a Mac security app: The Malware Scanner screen.

Additionally, Moonlock’s Malware Scanner can be scheduled and customized for speed and depth. No stone is unturned when scanning your Mac for the sort of hidden, dangerous files and malware that threat groups like Contiguous Interview are known to drop into your Mac.

The Moonlock app also ships with a Scam Detector. You can use it to check any email or text message for red flags, phishing, and scams, like those sent by fake job recruiters. 

Check out and test-drive Moonlock for free for 7 days. See how it feels on your end. 

Watch out for unsigned DMGs or software that comes with shady step-by-step instructions to install

Most of the malware posing a risk for Mac users cannot bypass Gatekeeper or any built-in security defenses. They require some social engineering from the attacker’s side. This means they must trick you into installing the malware yourself.

Being suspicious of apps that are not developer ID signed, or those that come with step-by-step instructions that ultimately seek to remove the Quarantine flag to avoid raising alarms on your Mac, is a good idea.

Even if an app is signed and installed through the normal path, this does not make it 100% safe. Double-check everything you install for safety and legitimacy. This goes for a browser extension, a DMG, or anything else. It’s the safe way to go.

If you are looking for a job or taking interviews, know the risks of fake recruiters

When contacted via LinkedIn or any other media with a job offer, there are certain red flags that security researchers highlight. These include offers that sound too good to be true, demands for sensitive information or personal data, upfront fees, take-home interview projects, and fake recruiters who insist that you download specific software to either video-chat or run coding tests or tests from other fields of work.  

Final thoughts 

Contagious Interview campaigns have been active since 2023, when Palo Alto Networks first spotted this campaign. For you, this campaign represents a risk if you are unfamiliar with the techniques that this threat group uses.

However, if you can recognize the techniques and understand how the malware breaches your Mac, you can avert the unpleasant scenario of an attacker gaining access to your computer, data, and accounts, including your crypto and finances. Be aware of how Contagious Interview evolves, because it does exactly that. It evolves constantly. Understanding this will give you an edge out in the wild. 

This is an independent publication, and it has not been authorized, sponsored, or otherwise approved by Apple Inc. Mac and macOS are trademarks of Apple Inc.

MoonLock Banner
Ray Fernandez

Ray Fernandez

Ray has been covering tech and cybersecurity for over 15 years. His work has appeared on TechRepublic, VentureBeat, Forbes, Entrepreneur, and the Microsoft Blog, among others.