Lazarus Group Launches ‘Mach-O Man’ Malware Attack Targeting Crypto and Fintech Firms
Lazarus Group is a hacking organization linked to the North Korean government that has long targeted the crypto industry to raise funds. Germany’s Baden-Württemberg State Office for the Protection of the Constitution estimates that the group has stolen about $6.7 billion in crypto assets since 2017. More than $500 million from recent operations has also been attributed to the group, making Macs used by corporate senior executives high-value entry points.
Researchers at ANY.RUN and BCA Ltd. disclosed “Mach-O Man” on April 21, 2026, and CertiK issued a warning the following day. Attackers send fake Zoom or Teams meeting invitations through Telegram and trick victims into pasting commands into a terminal. A four-stage program then steals browser credentials, cookies and macOS Keychain data, while installing a persistence mechanism that runs automatically after login.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.