Articles
Crypto Market Analysis

Lazarus-linked macOS malware hits crypto and fintech firms

User Image

توسط ناشناس

ایجاد شده April 22, 2026|2 دقیقه مطالعه
Main Image

Security researchers linked a new “Mach-O Man” malware kit to a Lazarus campaign that uses fake meeting invites and ClickFix prompts to steal credentials and access corporate systems on macOS.

Security researchers have linked a new macOS malware campaign to the Lazarus Group, the North Korea-linked hacking operation behind some of the crypto industry’s biggest thefts.

Flagged on Tuesday, the new “Mach-O Man” malware kit is distributed via “ClickFix” social engineering schemes across traditional businesses and crypto companies, according to Mauro Eldritch, offensive security expert and founder of threat intelligence company BCA Ltd.

Victims are lured into a fake Zoom or Google Meet call where they are prompted to execute commands that download the malware in the background, allowing attackers to bypass traditional controls without detection to gain access to credentials and corporate systems, the security researcher said in a Tuesday report.

Researchers said the campaign can lead to account takeovers, unauthorized infrastructure access, financial losses and the exposure of critical data, underscoring how Lazarus continues to expand its targeting beyond crypto-native companies.

The Lazarus Group is the main suspect in some of the largest-ever cryptocurrency hacks, including the $1.4 billion hack of Bybit exchange in 2025, the industry’s largest so far. 

The final stage of the campaign is a stealer designed to extract browser extension data, stored browser credentials, cookies, macOS Keychain entries and other sensitive information from infected devices.

After collection, the data is archived into a zip file and exfiltrated through Telegram to the attackers. Finally, the malware’s self-deletion script removes the entire kit using the system’s rm command, which bypasses user confirmation and permissions when removing files.

The novel malware kit was reconstructed by the security expert through cloud-based malware sandbox Any.run’s macOS analysis capabilities.

Related: CZ sounds alarm as ‘SEAL’ team uncovers 60 fake IT workers linked to North Korea

Earlier in April, North Korean hackers used AI-enabled social engineering schemes to steal about $100,000 worth of funds from crypto wallet Zerion, after gaining access to some team members’ logged-in sessions, credentials and the company’s private keys, Cointelegraph reported on April 15. 

Magazine: 53 DeFi projects infiltrated, 50M NEO tokens could be ‘given back’: Asia Express

Source: CoinTelegraph


مقالات دیگری که اخیرا منتشر شده است

Crypto investment firm Keyrock is acquiring bankrupt lender Blockfills
Crypto investment firm Keyrock is acquiring bankrupt lender Blockfills

Crypto Market Analysis

The Brussels-based digital asset services firm plans to purchase BlockFills months after the Chicago...

Strategy sold bitcoin in late May, and told the market in June. Here's how Polymarket bettors are fighting over when it counts.
Strategy sold bitcoin in late May, and told the market in June. Here's how Polymarket bettors are fighting over when it counts.

Bitcoin

A $79 million market hinges not on whether Michael Saylor's firm sold bitcoin, but on whether a sale...

Bitcoin slide to $70,000 as stocks pause and Strategy's BTC sale weighs on crypto
Bitcoin slide to $70,000 as stocks pause and Strategy's BTC sale weighs on crypto

Bitcoin

BTC fell 3.4% in 24 hours to below $71,000, the lowest level in weeks, as Monday's 8-K filing disclo...

Bitwise completes takeover of Superstate's $259M crypto carry fund
Bitwise completes takeover of Superstate's $259M crypto carry fund

Crypto Market Analysis

The transition gives the asset manager control of a tokenized fund that combines crypto carry trades...

DeFi protocol Radiant to wind down after failing to recover from 2024 hack
DeFi protocol Radiant to wind down after failing to recover from 2024 hack

DeFi

Radiant says its frontend and smart contracts will remain accessible and users will still be able to...

Strategy’s Bitcoin sale causes clash for $80M in Polymarket bets
Strategy’s Bitcoin sale causes clash for $80M in Polymarket bets

Bitcoin

A clash has erupted among Polymarket users over the timing and disclosure of a recent Bitcoin sale b...