Lazarus Group is using a new macOS malware campaign called “Mach-O Man” to go after Apple users in the crypto sector, according to a warning from CertiK. The campaign is aimed at Web3 executives. Attackers reportedly pose as business contacts, send urgent video meeting links, and then direct targets to paste a so-called fix for a connection issue into the Mac Terminal. Once the command is run, the attackers can gain access to internal systems, SaaS platforms, and financial resources.
More than $500 million stolen in the past two weeks
CertiK said Lazarus has stolen an estimated $6.7 billion since 2017. Natalie Newson, a senior blockchain security researcher at the firm, said the North Korean hacking group took more than $500 million over the last two weeks through attacks tied to the DeFi protocols Drift and KelpDAO. She said the KelpDAO incident, the Drift attack, and this new macOS malware suite all surfaced within the same month, pointing to a sustained and highly active operation.
How the “ClickFix” social engineering flow works
The delivery method relies on a social engineering tactic known as “ClickFix.” Based on analysis cited from CertiK and BCA Ltd founder Mauro Eldritch, attackers begin by sending urgent meeting requests through messaging apps such as Telegram. The invitation may appear to be for Zoom, Microsoft Teams, or Google Meet. After the victim clicks, they are taken to a convincing fake website that claims a connection issue needs to be fixed.
The trap is in the next step. The page tells the user to copy a command and run it in Terminal on their Mac. Because the action is carried out directly by the victim, standard security controls may fail to stop it. Newson said the page looks legitimate and the instructions appear routine, which helps the attack slip past conventional defenses while giving the attackers immediate access.
Built for Apple environments used across crypto and fintech
The report describes “Mach-O Man” as a modular macOS malware toolkit created by Lazarus’s Chollima unit. It uses native Mach-O binaries and is tailored for Apple environments commonly used in cryptocurrency and fintech operations. Security researcher Vladimir S. also pointed to another variation of the attack: threat actors hijack DeFi project domains and replace the site with a fake Cloudflare verification page that tells users to enter terminal commands to grant access.
Victims may not realize what happened until funds are gone
CertiK said the malware is designed to stay hidden. In many cases, victims only discover the breach after assets have already been drained. The challenge does not end there. The malware often deletes itself after execution, making it difficult for victims to determine which variant was used or how the compromise unfolded. For teams handling on-chain assets, enterprise wallets, or sensitive backend permissions, unsolicited terminal commands remain a direct security risk.

