The North Korean Lazarus Group uses macOS malware toolkit to attack cryptocurrency and fintech companies

By: rootdata|2026/04/22 20:48:29
0
Share
copy

According to CoinDesk, monitoring by CertiK reveals that the Lazarus Group is conducting an attack operation named Mach-O Man targeting executives in the fintech and cryptocurrency industries. This operation utilizes ClickFix social engineering techniques, sending fake online meeting invitations to lure victims into pasting repair commands on their Mac terminals, thereby gaining access to company and financial systems.

CertiK researcher Natalie Newson stated that the Lazarus Group has stolen over $500 million through attacks on Drift and KelpDAO in the past two weeks. Mach-O Man is a modular macOS malware toolkit developed by the Chollima division of the Lazarus Group, capable of automatically deleting itself after use to evade detection.

Additionally, attackers have implemented this attack by hijacking DeFi project domain names and replacing them with fake Cloudflare messages.

You may also like

Morning Report | DeepSeek completes over $7 billion in financing, with a valuation exceeding $50 billion; Musk's personal wealth has surpassed the total market value of Bitcoin

Overview of Important Market Events on June 16

Cursor, why did you get on Musk's spaceship?

SpaceX set a record with its IPO, spending a staggering $60 billion to acquire the popular AI programming unicorn Cursor just four days later. Musk is using the ultimate puzzle of "super computing power + top coding engine" to propel the market value skyrocketing, surpassing Amazon in one fell swoop...

In the name of charity, for the benefit of the family: How the Trump family turned charity into profit?

This set of "beautiful rhetoric and value return to one's own people" has not stopped at charitable foundations; it has now almost been transferred intact to American Bitcoin.

Will Gold Break $4,500 After Tonight's Fed Decision? What XAUT and PAXG Traders Need to Know

The Federal Reserve announces its June rate decision tonight. Could gold break $4,500 next? Explore the latest gold price prediction, key Fed scenarios, and what they mean for XAUT and PAXG traders.

SharpLink CEO: How to understand that Ethereum developers have just surpassed 1 million?

The most important question in the cryptocurrency industry is not which chain is the fastest, but rather where top builders choose to build in the long term. Ethereum has just surpassed one million cumulative developers; what does this number mean?

Morning Report | MiCA grace period expires on July 1; Kalshi's trading volume in the first week of the World Cup breaks $5.1 billion, setting a record

Overview of Important Market Events on June 15

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com