Lazarus Group Mach-O Man ClickFix macOS Campaign
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
Summary
In April 2026, researchers at Bitso's Quetzal Team and ANY.RUN disclosed a new macOS attack campaign attributed to North Korea's Lazarus Group, dubbed 'Mach-O Man.' The campaign uses a ClickFix social engineering technique — delivering fake online meeting invitations via Telegram that trick targets into pasting malicious terminal commands — to deploy a modular, Go-compiled malware kit targeting crypto and fintech executives. CertiK's Natalie Newson publicly characterized the campaign as part of an intensified Lazarus operational tempo that also encompassed the alleged theft of over $575 million from DeFi platforms Drift Protocol and KelpDAO in April 2026.
Connected Entities
1 entitiesTimeline(7 events)
1 April 2026
Drift Protocol reportedly suffered a loss of approximately $285 million in an incident attributed by multiple sources to Lazarus Group, though no court or regulatory determination has been made.
CryptoSlate18 April 2026
KelpDAO's LayerZero bridge was exploited for approximately $292 million in rsETH. LayerZero and Chainalysis attributed the exploit to Lazarus Group's TraderTraitor subunit, based on on-chain and infrastructure analysis.
Yahoo Finance / LayerZero21 April 2026
Bitso's Quetzal Team researcher Mauro Eldritch, in collaboration with ANY.RUN, publicly disclosed the Mach-O Man malware campaign, publishing SHA-256 hashes for all major components and network indicators of compromise.
ANY.RUN Cybersecurity Blog22 April 2026
CoinDesk published reporting on the Mach-O Man campaign, featuring analysis from CertiK senior researcher Natalie Newson, who characterized the campaign as converting business communications into credential theft pathways and linked it to an elevated Lazarus operational tempo.
CoinDesk22 April 2026
Security researchers publicly recommended defensive actions including blocking Terminal-based ClickFix lures and auditing LaunchAgent directories for OneDrive-masquerading persistence artifacts.
ANY.RUN / CryptoTimes23 April 2026
Chainalysis published a technical post-mortem of the KelpDAO bridge exploit, characterizing it as a sophisticated off-chain infrastructure attack rather than a smart contract vulnerability.
Chainalysis29 April 2026
CybersecurityNews published an extended analysis of the Mach-O Man malware kit, further documenting the four-stage attack chain and confirming Mauro Eldritch and ANY.RUN as primary researchers.
CybersecurityNewsDecision Log
- #1publish⛓ pending9/1/2026, 12:41:06 PMhash: CvZYDnumXRdJzVEYh3DAPt8o4yRNScjD3PrfuQ19jA6o
14 of 17 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/1/2026, 12:40:56 PM
last updated: 9/1/2026, 3:37:56 PM
avoid.net — verified advice for a post-truth world