BotBeat
...
← Back

> ▌

N/AN/A
INDUSTRY REPORTN/A2026-04-21

Lazarus Group Launches 'Mach-O Man' macOS Malware Campaign Targeting Fintech and Crypto Businesses

Key Takeaways

  • ▸Lazarus Group is actively distributing a new macOS malware kit through fake meeting invitations sent via Telegram, targeting business leaders in fintech and crypto sectors
  • ▸The attack uses ClickFix social engineering techniques that prompt users to execute commands to 'fix' connection issues, bypassing traditional security controls
  • ▸Compromised macOS devices provide attackers with full access to credentials, browser sessions, and Keychain data—enabling account takeovers and infrastructure compromise
Source:
Hacker Newshttps://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/↗

Summary

Security researchers have identified a new active campaign by the Lazarus Group that uses fake meeting invitations and social engineering to distribute a newly discovered macOS malware kit. The attack leverages ClickFix techniques, where victims are tricked into executing commands on their systems through fake collaboration platform interfaces mimicking Zoom, Microsoft Teams, or Google Meet. The campaign specifically targets fintech, cryptocurrency, and high-value environments where macOS is prevalent among developers, executives, and decision-makers.

Once executed, the malware collects sensitive credentials, browser sessions, and macOS Keychain data—providing attackers direct access to corporate systems, SaaS platforms, and financial assets. The stolen data is exfiltrated through Telegram, a legitimate service that helps attackers blend their activities into normal network traffic. The attack is particularly dangerous because it bypasses traditional endpoint detection and response (EDR) tools by relying on user execution of native macOS binaries rather than software vulnerabilities.

  • The campaign is difficult to detect because it relies on social engineering and native macOS binaries, reducing visibility for traditional EDR tools
Finance & FintechCybersecurity

More from N/A

N/AN/A
POLICY & REGULATION

Australian Privacy Watchdog's Warnings Ignored in Teen Social Media Ban Tech Trial

2026-04-21
N/AN/A
POLICY & REGULATION

Critical Drag-and-Drop Vulnerability Discovered in Popular Terminal Emulators

2026-04-21
N/AN/A
RESEARCH

Researchers Develop Verified Deep Learning Framework Using Lean 4 Proof Assistant

2026-04-21

Comments

Suggested

AnthropicAnthropic
POLICY & REGULATION

Unauthorized Group Gains Access to Anthropic's Mythos Cybersecurity Tool Through Third-Party Vendor

2026-04-22
AnthropicAnthropic
RESEARCH

Mozilla Reports Anthropic's Mythos Found 271 Security Vulnerabilities in Firefox 150, Marking AI Turning Point in Cybersecurity

2026-04-21
AnthropicAnthropic
RESEARCH

Anthropic's Claude Mythos Security Claims Face Scrutiny Over Verification Gap

2026-04-21
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us