Mark RadarMARK RADAR
EN
Event File CRYPTO Cybersecurity

Lazarus Group Launches ‘Mach-O Man’ Malware Attack Targeting Crypto and Fintech Firms

3 reports · First detected 2026-04-22 · Last active 2026-04-23

Lazarus Group is a hacking organization linked to the North Korean government that has long targeted the crypto industry to raise funds. Germany’s Baden-Württemberg State Office for the Protection of the Constitution estimates that the group has stolen about $6.7 billion in crypto assets since 2017. More than $500 million from recent operations has also been attributed to the group, making Macs used by corporate senior executives high-value entry points.

Researchers at ANY.RUN and BCA Ltd. disclosed “Mach-O Man” on April 21, 2026, and CertiK issued a warning the following day. Attackers send fake Zoom or Teams meeting invitations through Telegram and trick victims into pasting commands into a terminal. A four-stage program then steals browser credentials, cookies and macOS Keychain data, while installing a persistence mechanism that runs automatically after login.

All Coverage

3 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR