Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Lazarus Group Targets Crypto Firms With “Mach-O Man”: Certik

The campaign is designed to steal sensitive data like login credentials, browser data, and crypto-related access keys from high-value targets.

Written By Iyiola Adrian
Fact Checked by Shubham Soni
Published 2026-04-22·Updated 5 months ago
Make The Crypto Times preferred on GoogleGoogle
Lazarus Group Targets Crypto Firms With “Mach-O Man” Certik

Key Highlights

  • Lazarus Group is running a macOS-focused cyber campaign called “Mach-O Man,” targeting crypto and fintech workers.
  • The attack uses social engineering to trick users into running a Terminal command that installs malware to steal private information.
  • The group has stolen billions in crypto over the years and continues to use more advanced methods like this campaign.

A senior blockchain security researcher at Certik reportedly said that North Korea’s Lazarus Group is running a new macOS-focused campaign called the “Mach-O Man.”

According to a report, the campaign is said to target macOS users working in crypto, fintech, and other high-value companies.

How the “Mach-O Man” campaign works

Security analyst ANY.RUN provided a detailed review of the attack. The campaign usually starts on Telegram. A victim receives what looks like a normal meeting invite, often from someone they already know or trust, because the account has been hacked.

Lazarus Group Just Released “Mach-O Man” – A Brand-New Native macOS Malware Kit Targeting Fintech, Crypto, and High-Value Executives

You get an “urgent” meeting invite over Telegram for a Zoom, Teams, or Google Meet call. The link leads to a convincing fake website that tells…

— Vladimir S. | Officer's Notes (@officer_secret) April 21, 2026

The message then tells the victim to join a meeting on platforms like Zoom, Microsoft Teams, or Google Meet. After clicking, they are sent to a fake support page that says there is a problem with joining the meeting. The page then asks the user to copy and paste a command into macOS Terminal to fix the issue. This is the key step used to install the malware.

Once the command runs, a first-stage malware file is activated. It downloads a fake macOS application that looks like regular software uses built-in system tools, so it looks “trusted” to macOS security checks, which helps it avoid being blocked by basic protections and makes it harder for users to notice anything wrong.

Inside the malware system

According to ANY.RUN, the malware package is built using Go-based Mach-O binaries and is split into several parts. One component acts as a stager that launches the infection process. Another part collects system information from the device, including the computer name, operating system version, CPU details, network setup, running programs, and browser extensions.

It also checks popular browsers like Chrome, Safari, Firefox, Brave, Opera, and Vivaldi. All this data is packed together and sent back to the hacker using Telegram.

Another module is built to stay inside the system for a long time. It hides files in system folders and uses startup features on macOS, so it runs every time the computer is turned on. This means even if the system is restarted, the malware does not go away.

A final module focuses on stealing sensitive data, including browser cookies, stored login details, and macOS Keychain information. The stolen data is packed into archive files and sent to attackers using Telegram bot infrastructure.

Security researchers also noted that the malware includes cleanup features that attempt to remove traces after stealing data. Some parts of the code are poorly built, and there are mistakes like exposed bot tokens, but it still works because users are tricked into running the commands themselves.

Why security measures matter 

The risk for crypto and fintech firms is high. If one computer is infected, attackers may gain access to wallet seed phrases, exchange API keys, internal admin tools, and company systems. From there, they can move deeper into networks or even carry out illegal transactions without permission.

Lazarus Group has been linked to multiple large-scale crypto attacks over the years. The group has stolen billions of dollars in digital assets since 2017, using a mix of hacking, social engineering, and long-term infiltration tactics.

Recently, the group was linked to an exploit on KelpDAO, in which they stole about $290 million, and to the Bybit exchange exploit. In fact, the group had, in total, taken about $7.3 billion from crypto firms in the last four years.

The group also uses methods beyond direct hacking, including fake identities and insider access, to infiltrate organizations over time before executing attacks.

Also Read: Kelp DAO Hacker Routes Stolen Funds to Tron in Fresh Laundering Push

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto HackNorth Korea
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

SingularityNET Bridge Hack Widens: 260M AGIX, 53.8M WMTx Minted, $16.77M Held by Attacker
SingularityNET Bridge Hack Widens: 260M AGIX, 53.8M WMTx Minted, $16.77M Held by Attacker
Polymarket Hit by $10M Stolen-Card Fraud Attempt as CEO Told Staff to Keep Growing: WSJ
Polymarket Hit by $10M Stolen-Card Fraud Attempt as CEO Told Staff to Keep Growing: WSJ
Fetch.ai and NuNet Hit by $2M Exploit, NTX Crashes Over 65% in Hours
Fetch.ai and NuNet Hit by $2M Exploit, NTX Crashes Over 65% in Hours
CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
Interpol emblem and uppercase lettering mounted on a building exterior.
INTERPOL Identifies $41M in Assets Through Silver Notice Programme

Find Us on Socials

You may also like

Smartphone showing the BitGo logo set in front of an illuminated BitGo wall sign.

BitGo Powers Bitcoin Payments for Toyota Dealer in Bolivia

Dark blue Visa card standing in front of an illuminated Visa sign and POS terminal.

Visa Moves to Change How Memecoin Card Purchases Are Classified

Smartphone showing an Injective price chart at $7.53 in front of the Injective logo screen.

Injective’s INJ Token Surpasses $7.50 After Solana Expansion and ETF Filing

Illuminated Blink Bitcoin logo display beside a hooded figure and a cyber threat alert.

Blink Wallet Pauses Services After Attack on Custodial Accounts

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information