Lazarus Group’s Mach-O Man malware targets crypto sector
Lazarus Group's "Mach-O Man" malware targets macOS crypto and fintech users with fake meeting invites, stealing credentials and evading detection. High-value executives and developers are at risk.
North Korea's Lazarus Group has launched a sophisticated cyber campaign called "Mach-O Man," specifically targeting macOS users in the crypto and fintech industries. The attackers use advanced social engineering, sending urgent meeting invitations through platforms like Telegram, Zoom, or Google Meet, often from compromised accounts. Victims are redirected to fake support pages that instruct them to run a Terminal command, which installs modular malware. This malware can steal credentials, browser sessions, and macOS Keychain data. It is designed to run natively on both Apple Silicon and Intel Macs, and can self-destruct to avoid detection. The campaign is tailored for high-value targets such as executives and developers. Researchers have linked it to recent large-scale crypto thefts and warn that traditional security measures are less effective due to the user-driven infection method. Organizations should block Terminal-based lures and audit for suspicious LaunchAgents to strengthen their defenses.