Skip to main content
Sign in

Lazarus Group Mach-O Man ClickFix macOS Campaign

avoid.net/lazarus-group-mach-o-man-clickfix-macos-campaign0/100·91% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

In April 2026, researchers at Bitso's Quetzal Team and ANY.RUN disclosed a new macOS attack campaign attributed to North Korea's Lazarus Group, dubbed 'Mach-O Man.' The campaign uses a ClickFix social engineering technique — delivering fake online meeting invitations via Telegram that trick targets into pasting malicious terminal commands — to deploy a modular, Go-compiled malware kit targeting crypto and fintech executives. CertiK's Natalie Newson publicly characterized the campaign as part of an intensified Lazarus operational tempo that also encompassed the alleged theft of over $575 million from DeFi platforms Drift Protocol and KelpDAO in April 2026.

Connected Entities

1 entities
Protocols
Lazarus Group Mach-O Man ClickFix macOS Campaign
Relationships
    Have evidence about Lazarus Group Mach-O Man ClickFix macOS Campaign?

    Timeline(7 events)

    1 April 2026

    Drift Protocol reportedly suffered a loss of approximately $285 million in an incident attributed by multiple sources to Lazarus Group, though no court or regulatory determination has been made.

    CryptoSlate

    18 April 2026

    KelpDAO's LayerZero bridge was exploited for approximately $292 million in rsETH. LayerZero and Chainalysis attributed the exploit to Lazarus Group's TraderTraitor subunit, based on on-chain and infrastructure analysis.

    Yahoo Finance / LayerZero

    21 April 2026

    Bitso's Quetzal Team researcher Mauro Eldritch, in collaboration with ANY.RUN, publicly disclosed the Mach-O Man malware campaign, publishing SHA-256 hashes for all major components and network indicators of compromise.

    ANY.RUN Cybersecurity Blog

    22 April 2026

    CoinDesk published reporting on the Mach-O Man campaign, featuring analysis from CertiK senior researcher Natalie Newson, who characterized the campaign as converting business communications into credential theft pathways and linked it to an elevated Lazarus operational tempo.

    CoinDesk

    22 April 2026

    Security researchers publicly recommended defensive actions including blocking Terminal-based ClickFix lures and auditing LaunchAgent directories for OneDrive-masquerading persistence artifacts.

    ANY.RUN / CryptoTimes

    23 April 2026

    Chainalysis published a technical post-mortem of the KelpDAO bridge exploit, characterizing it as a sophisticated off-chain infrastructure attack rather than a smart contract vulnerability.

    Chainalysis

    29 April 2026

    CybersecurityNews published an extended analysis of the Mach-O Man malware kit, further documenting the four-stage attack chain and confirming Mauro Eldritch and ANY.RUN as primary researchers.

    CybersecurityNews
    Provenance & Audit Trail
    14 Wayback Archives

    Decision Log

    • #1publish⛓ pending9/1/2026, 12:41:06 PM
      hash: CvZYDnumXRdJzVEYh3DAPt8o4yRNScjD3PrfuQ19jA6o

    14 of 17 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 9/1/2026, 12:40:56 PM

    last updated: 9/1/2026, 3:37:56 PM

    avoid.net — verified advice for a post-truth world