Lazarus Targets Mac Executives With ‘Mach-O Man’ Malware Through Fake Meeting Links

Lazarus Targets Mac Executives With ‘Mach-O Man’ Malware Through Fake Meeting Links

N
News Editor 01
2026-07-23 01:55:15
CertiK says Lazarus Group is deploying a new macOS malware set called “Mach-O Man,” using fake business meeting links to trick Web3 executives into running terminal commands that hand over system access.
Lazarus GroupmacOScybersecurityWeb3malware

Lazarus Group is using a new macOS malware campaign called “Mach-O Man” to go after Apple users in the crypto sector, according to a warning from CertiK. The campaign is aimed at Web3 executives. Attackers reportedly pose as business contacts, send urgent video meeting links, and then direct targets to paste a so-called fix for a connection issue into the Mac Terminal. Once the command is run, the attackers can gain access to internal systems, SaaS platforms, and financial resources.

More than $500 million stolen in the past two weeks

CertiK said Lazarus has stolen an estimated $6.7 billion since 2017. Natalie Newson, a senior blockchain security researcher at the firm, said the North Korean hacking group took more than $500 million over the last two weeks through attacks tied to the DeFi protocols Drift and KelpDAO. She said the KelpDAO incident, the Drift attack, and this new macOS malware suite all surfaced within the same month, pointing to a sustained and highly active operation.

How the “ClickFix” social engineering flow works

The delivery method relies on a social engineering tactic known as “ClickFix.” Based on analysis cited from CertiK and BCA Ltd founder Mauro Eldritch, attackers begin by sending urgent meeting requests through messaging apps such as Telegram. The invitation may appear to be for Zoom, Microsoft Teams, or Google Meet. After the victim clicks, they are taken to a convincing fake website that claims a connection issue needs to be fixed.

The trap is in the next step. The page tells the user to copy a command and run it in Terminal on their Mac. Because the action is carried out directly by the victim, standard security controls may fail to stop it. Newson said the page looks legitimate and the instructions appear routine, which helps the attack slip past conventional defenses while giving the attackers immediate access.

Built for Apple environments used across crypto and fintech

The report describes “Mach-O Man” as a modular macOS malware toolkit created by Lazarus’s Chollima unit. It uses native Mach-O binaries and is tailored for Apple environments commonly used in cryptocurrency and fintech operations. Security researcher Vladimir S. also pointed to another variation of the attack: threat actors hijack DeFi project domains and replace the site with a fake Cloudflare verification page that tells users to enter terminal commands to grant access.

Victims may not realize what happened until funds are gone

CertiK said the malware is designed to stay hidden. In many cases, victims only discover the breach after assets have already been drained. The challenge does not end there. The malware often deletes itself after execution, making it difficult for victims to determine which variant was used or how the compromise unfolded. For teams handling on-chain assets, enterprise wallets, or sensitive backend permissions, unsolicited terminal commands remain a direct security risk.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.