Lazarus Group Launches macOS Hacks via Fake Calls

3 Min Read Tags:

  • Lazarus Group, a notorious North Korean hacker collective, has launched a new macOS-targeted attack campaign called Mach-O Man.
  • The attack exploits social engineering tactics, disguising malware as a connectivity issue fix and targeting fintech and crypto companies.
  • This sophisticated strategy uses phishing methods involving fake online meeting invitations via platforms like Zoom and Google Meet.
  • Analysts warn of significant financial implications, with losses from these attacks reaching nearly $600 million.

Lazarus Group Launches Wave of Hacker Attacks through Fake Calls to Breach macOS

The digital landscape is witnessing another alarming development with the introduction of the Mach-O Man campaign by the infamous North Korean hacker group, Lazarus. This latest wave specifically targets macOS users within fintech and cryptocurrency sectors. With their strategic use of social engineering disguised as legitimate business communications, Lazarus Group continues to pose escalating threats to crypto enterprises globally.

Anatomy of the Attack

Lazarus Group’s recent activities focus on exploiting typical business communications. The attackers send seemingly urgent meeting invitations through Telegram for platforms such as Zoom or Google Meet. These links redirect unsuspecting victims to convincing fake websites where they are prompted to execute commands in their terminal under the guise of fixing connection issues. This clever use of the ClickFix method ultimately grants hackers unauthorized access to systems.

A New Level of Threat

The Mach-O Man campaign represents a significant leap in malware sophistication. Using native macOS binaries allows this modular malware kit to evade detection effectively. Once its task is complete, it can self-destruct, leaving minimal traces for cybersecurity teams to analyze.

Targets and Implications

Primarily aiming at leaders and employees within fintech firms and digital asset companies, this campaign has already been adopted by other cybercriminal groups beyond North Korea. Recent incidents linked to this group include breaches involving KelpDAO and Drift Protocol, resulting in substantial financial losses estimated at nearly $600 million.

Broader Impact on Crypto Security

Experts emphasize that such coordinated attacks should be viewed as systemic threats rather than isolated incidents. The scale and precision observed suggest state-level coordination, greatly complicating defense efforts for affected organizations. Many victims remain unaware until damage occurs due to the stealthy nature of these attacks.
In light of these developments, it is crucial for those involved in cryptocurrency operations to bolster their cybersecurity measures proactively. The evolving tactics employed by groups like Lazarus underscore an urgent need for heightened awareness and robust defenses against increasingly sophisticated cyber threats in the crypto industry.

TAGGED:
Canary Capital Launches First US Spot TRX ETF With Staking

Canary Capital launched the Canary Staked TRX ETF on Cboe BZX under ticker TRXS on Sept. 9, 2026, offering direct TRX exposure and staking rewards.

5 Min Read
Anthropic Models 3 US Economic Scenarios Through 2030

Anthropic published a model outlining three scenarios for the U.S. economy through 2030, with its extreme scenario suggesting annual GDP growth could reach 15% alongside historically high unemployment.

7 Min Read
Robinhood CEO Says Companies Cannot Control Tokenization of Their Shares

In September 2026, Robinhood CEO Vlad Tenev said companies cannot prevent third-party products linked to their shares, defending 1:1 share-backed Stock Tokens after AMC CEO Adam Aron challenged their legality.

5 Min Read
Germany Will Change Crypto-Asset Tax Rules in 2027, Media Reports

Germany’s draft crypto tax reforms would from Jan. 1, 2027, tax profits on covered assets acquired after Dec. 31, 2026, regardless of holding period, while platforms would begin withholding tax…

5 Min Read
Vitalik Buterin Says Recursive STARKs Could Cut Ethereum Private, Post-Quantum Transaction Costs

On Sept. 9, Ethereum co-founder Vitalik Buterin explained EIP-8288, a proposal to aggregate STARK proofs and cryptographic signatures at the mempool level, potentially reducing costs without changing the EVM.

6 Min Read