Lazarus Group Targets macOS Users with New Mach-O Man Malware Arsenal
North Korean hacking group Lazarus Group is deploying modular macOS malware through fake video call invitations on Zoom, Teams, and Google Meet, targeting crypto and fintech companies.
New North Korean malware arsenal targets crypto ecosystem
North Korea-linked Lazarus Group has launched a widespread campaign using a new modular macOS malware toolkit dubbed Mach-O Man. Cybersecurity researcher Mauro Eldritch disclosed the threat and its distribution methods.
«Lazarus is back with a new macOS malware kit. Made up of multiple Mach-O binaries, we named it "Mach-O Man". It is being distributed via ClickFix in the crypto ecosystem to steal secrets» — Mauro Eldritch (@MauroEldritch), original post
According to Eldritch, the arsenal was developed by another North Korean hacking group known as Famous Chollima. The toolkit consists of native Mach-O binary files specifically crafted for Apple's ecosystem — a platform widely adopted by crypto and fintech companies.
How the ClickFix attack works
The malware is delivered through a social engineering technique called ClickFix. Attackers send victims an "urgent" video call invitation via Telegram, purportedly for a meeting on Zoom, Microsoft Teams, or Google Meet.

The link in the invitation redirects to a phishing site that instructs the user to copy and paste a simple command into their Mac terminal — ostensibly to "fix a connection issue." Once executed, the command grants attackers direct access to corporate systems, SaaS platforms, and financial resources. In most cases, the breach is discovered too late to prevent damage.
DeFi domain hijacking adds another attack vector
Cybersecurity researcher Vladimir S. highlighted several variations of the attack described by Eldritch. In some instances, Lazarus hackers have been observed hijacking DeFi project domains and replacing the websites with fake Cloudflare messages asking users to enter a command to "grant access."
«I also once seen a slightly different variation of the attack where the attackers hijacked the DeFi project's domain and replaced the website with a fake message from Cloudflare asking users to enter a command to grant access. A lot of people fell for it» — Vladimir S. | Officer's Notes (@officer_secret), original post
Why this matters
Lazarus Group is operating at an unprecedented pace. CertiK senior blockchain security researcher Natalie Newson noted that attacks on Kelp, Drift, and the release of the new macOS arsenal all occurred within a single month. She characterized the activity not as random hacks but as a state-sponsored financial operation running at institutional scale and tempo.
The threat extends beyond technical exploits. In April, an Ethereum Foundation fellow identified approximately 100 North Korean IT agents embedded within Web3 companies. An on-chain detective had previously uncovered a similar network of DPRK operatives in the crypto industry.
macOS users working in the crypto sector should exercise extreme caution when receiving unexpected video conference invitations, particularly through messaging apps, and should never paste unfamiliar commands into their terminal under any circumstances.
Frequently Asked Questions
What is Mach-O Man malware from Lazarus Group?
Mach-O Man is a new modular macOS malware toolkit developed by North Korean group Famous Chollima and deployed by Lazarus Group. It consists of native Mach-O binary files designed for Apple's ecosystem and is distributed via a social engineering technique called ClickFix targeting crypto and fintech companies.
How does the Lazarus ClickFix attack work on Mac?
Attackers send fake urgent video call invitations via Telegram for Zoom, Teams, or Google Meet. The link leads to a phishing site that instructs users to paste a command into their Mac terminal to supposedly fix a connection issue. Executing the command gives hackers direct access to corporate systems and financial resources.
Which crypto projects were targeted by Lazarus Group in 2026?
According to CertiK senior researcher Natalie Newson, Lazarus Group attacked Kelp and Drift and released the new Mach-O Man macOS arsenal all within a single month. She described the activity as a state-sponsored financial operation running at institutional scale.
How to protect against ClickFix macOS malware attacks?
Never paste unfamiliar commands into your Mac terminal under any circumstances. Be extremely cautious of unexpected video conference invitations received through messaging apps like Telegram. Always verify the authenticity of links and the identity of senders before clicking.
Are North Korean agents working inside Web3 companies?
Yes, in April 2026, an Ethereum Foundation fellow identified approximately 100 North Korean IT agents embedded within Web3 companies. An on-chain detective had also previously uncovered a similar network of DPRK operatives in the crypto industry.
Read also
Ethereum Address Poisoning Attacks Surge 612% After Fusaka Upgrade
The Fusaka upgrade's reduced gas fees have triggered an explosion in address poisoning attacks on Ethereum, with dust transfers of USDT soaring 612% in just 90 days.
Over $8.6B Drained From Aave as Kelp DAO Hack Triggers Massive DeFi Exodus
Aave's TVL plunged from $26.3B to $17.7B in two days after hackers exploited Kelp DAO's cross-chain bridge, stealing $293M in rsETH and creating $195M in bad debt across lending protocols.
AI Audit Uncovers Critical Liveness Bug in Ethereum's Nethermind Client
Octane Security's AI discovered a high-severity vulnerability in the Nethermind execution client that could have halted block production for 38% of Ethereum mainnet validators. The Ethereum Foundation awarded a maximum $50,000 bounty.
April 2026 Sets All-Time Record for Number of Crypto Hacks
April 2026 saw a record-breaking 24 crypto hacks resulting in approximately $651 million in total losses. Kelp and Drift Protocol suffered the largest exploits.
Weekly Recap: NYT Satoshi Investigation, North Korean Hackers in DeFi, and Anthropic's AI 'Escape'
Bitcoin climbed above $71,000, a NYT journalist named Adam Back as Satoshi Nakamoto, ZachXBT exposed a network of North Korean IT agents in crypto projects, and Anthropic shelved its new AI model after it escaped a sandbox and found thousands of zero-day vulnerabilities.
GPU Memory Attacks, $21B in Cybercrime Losses, and Chrome's Chip-Level Protection: Cybersecurity Roundup
The FBI reported record $21 billion in cybercrime losses for 2025, Google introduced hardware-bound session protection in Chrome, and researchers demonstrated three new attack methods targeting Nvidia GPU memory.
