Lazarus Group Launches ‘Mach-O Man’ Malware Attack Targeting Crypto and Fintech Firms
Lazarus Group is a hacking organization linked to the North Korean government that has long targeted the crypto industry to raise funds. Germany’s Baden-Württemberg State Office for the Protection of the Constitution estimates that the group has stolen about $6.7 billion in crypto assets since 2017. More than $500 million from recent operations has also been attributed to the group, making Macs used by corporate senior executives high-value entry points.
Researchers at ANY.RUN and BCA Ltd. disclosed “Mach-O Man” on April 21, 2026, and CertiK issued a warning the following day. Attackers send fake Zoom or Teams meeting invitations through Telegram and trick victims into pasting commands into a terminal. A four-stage program then steals browser credentials, cookies and macOS Keychain data, while installing a persistence mechanism that runs automatically after login.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →