In this presentation, we share details of our investigation into nation-state activity linked to the DPRK, involving the use of fake job interviews. These operations impersonate legitimate recruiters from the tech industry to target software developers, particularly those working in the cryptocurrency sector. During our investigation, we observed and analyzed various TTPs associated with DPRK-linked threat actors, but what stood out most was our discovery of a previously undocumented macOS malware strain that exhibits a range of sophisticated and unusual capabilities. This strain leverages AppleScript (osascript) for command execution and persistence, and maintains separate memory streams for command and control (C2) communication. Up until this investigation, Koi Stealer had only been observed targeting the Windows operating system, and had not been linked to nation-state threat actors. We used several lines of evidence to link the macOS variant to its Windows counterpart, and to attribute the activity to DPRK-aligned threat actors: * TTP Correlation: The attack patterns align with known tactics, techniques, and procedures (TTPs) associated with North Korean groups, especially their use of social engineering through fake job offers to lure victims. * Code Similarity Analysis: We identified significant overlaps in code structure, encryption routines, and similar C2 communication between the new macOS variant and its Windows predecessor. * Infrastructure Pivoting: By tracing the C2 infrastructure, we were able to link the campaign to previously known North Korean operations, and to identify that one of the C2 servers was also being used by the Windows variant of Koi Stealer.