← Lazarus Group Mach-O Man macOS Campaign — 20261 decision on this page
Audit log
Every state-changing event for Lazarus Group Mach-O Man macOS Campaign — 2026: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-07 12:26:11ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
97dYL5p7Pbz9…9uy1w8T4sha256 → base58
verifying row…canonical bytes (31233 B) ▸
{"actor":"system:backfill","investigation_id":"e9d60bed-425b-4fc6-b70b-15d7d8e9722d","kind":"publish","page_slug":"lazarus-group-mach-o-man-macos-campaign-2026","published_at":"2026-08-07T12:26:11.702Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Lazarus Group Mach-O Man macOS Campaign — 2026","sections":[{"content":"The Mach-O Man campaign is attributed to the Lazarus Group, a North Korean state-sponsored advanced persistent threat actor linked to the Reconnaissance General Bureau (RGB), Pyongyang's primary foreign intelligence directorate. The group operates under numerous aliases documented by the US government and cybersecurity vendors, including Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, and Diamond Sleet. OFAC designated Lazarus Group on April 14, 2022, under North Korea Sanctions Regulations section 510.214, placing it on the Specially Designated Nationals (SDN) list. The Mach-O Man kit was specifically engineered by the Chollima sub-unit, which has historically focused on financially motivated intrusions against cryptocurrency and financial targets. The group has been operational since at least 2009 and is responsible for the 2014 Sony Pictures Entertainment breach, the 2016 Bangladesh Bank SWIFT heist, and a series of multi-hundred-million-dollar cryptocurrency platform exploits including the $625 million Ronin Network hack in 2022 and the $1.5 billion Bybit breach in early 2025. Cumulative attributed theft since 2017 is estimated by TRM Labs at over $6 billion.","heading":"Attribution and Background","severity":"critical","sources":[{"credibility":2,"name":"CoinDesk: Lazarus Group Mach-O Man attack — CertiK","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/22/lazarus-group-has-become-especially-dangerous-with-new-mach-o-man-attack-certik"},{"credibility":1,"name":"MITRE ATT&CK: Lazarus Group (G0032)","type":"research","url":"https://attack.mitre.org/groups/G0032/"},{"credibility":1,"name":"OpenSanctions: Lazarus Group SDN listing","type":"regulatory","url":"https://www.opensanctions.org/entities/NK-Xv8CnM8sgddxx7QenotGtb/"},{"credibility":1,"name":"OFAC Treasury SDN Designation (April 2022)","type":"regulatory","url":"https://ofac.treasury.gov/recent-actions/20220422"}]},{"content":"The Mach-O Man malware kit was publicly disclosed on April 21–22, 2026, by researchers at Bitso's Quetzal Team (led by Mauro Eldritch) working in collaboration with the ANY.RUN interactive sandbox platform. The research team named the broader intrusion cluster 'North Korea's Safari,' reflecting the campaign's focus on macOS targets. CertiK security analyst Natalie Newson simultaneously flagged the campaign and connected it to a concentrated wave of Lazarus-attributed thefts in the same month, including the Drift Protocol and KelpDAO exploits. The ANY.RUN blog published a detailed CISO-oriented technical breakdown including indicators of compromise. The campaign was also independently covered by CoinDesk, Dark Reading, Cryptopolitan, GBHackers, and CyberSecurityNews.","heading":"Campaign Discovery and Research Attribution","severity":"high","sources":[{"credibility":2,"name":"ANY.RUN Blog: Lazarus Mach-O Man Malware — What CISOs Need to Know","type":"research","url":"https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/"},{"credibility":2,"name":"Bitso Quetzal Team — Mauro Eldritch (Substack)","type":"research","url":"https://quetzal.bitso.com/"},{"credibility":2,"name":"CoinDesk: Lazarus Group Mach-O Man attack — CertiK","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/22/lazarus-group-has-become-especially-dangerous-with-new-mach-o-man-attack-certik"},{"credibility":2,"name":"GBHackers: Lazarus Targets macOS Users With Mach-O Man Malware Kit","type":"news_article","url":"https://gbhackers.com/lazarus-targets-macos-users/amp/"}]},{"content":"The campaign's initial infection vector is a social engineering technique known as ClickFix. Attackers contact targets via Telegram, frequently using accounts compromised from known colleagues or business contacts in order to establish apparent legitimacy. The target receives a fake invitation to a video conference on Zoom, Microsoft Teams, or Google Meet. Upon attempting to join, the victim is redirected to a phishing page that displays a simulated connection error and instructs the user to paste a remediation command into the macOS Terminal. Because the user voluntarily executes the command, this approach bypasses traditional endpoint security controls that depend on detecting exploit code rather than user-initiated execution. The approach is distinct from prior Lazarus macOS campaigns (such as AppleJeus and RustBucket) that relied on trojanized applications or direct exploits. The use of ClickFix reflects a broader industry-wide trend of social-engineering-based initial access observed across multiple threat actors in 2025–2026.","heading":"Attack Vector — ClickFix Social Engineering","severity":"critical","sources":[{"credibility":2,"name":"ANY.RUN Blog: Lazarus Mach-O Man Malware — What CISOs Need to Know","type":"research","url":"https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/"},{"credibility":2,"name":"Cryptopolitan: Lazarus Group targets crypto, high-value execs with Mach-O Man","type":"news_article","url":"https://www.cryptopolitan.com/lazarus-group-malware-kit-macos-crypto-execs/"},{"credibility":2,"name":"Dark Reading: North Korea's Lazarus Targets macOS Users via ClickFix","type":"news_article","url":"https://www.darkreading.com/threat-intelligence/north-koreas-lazarus-targets-macos-users-clickfix"}]},{"content":"Mach-O Man is a modular, Go-compiled malware kit distributed as native Mach-O binaries compatible with both Intel x86-64 and Apple Silicon (arm64) architectures. The kit operates in four to five distinct stages. Stage 1 (teamsSDK.bin): The initial stager downloads a fake application bundle impersonating a legitimate video-conferencing platform. It uses the macOS codesign utility to apply an ad-hoc code signature, presenting an appearance of legitimacy to macOS Gatekeeper. The application presents a credential prompt in broken English; the first two submission attempts trigger a window-shake animation simulating authentication failure, while the third silently captures and transmits credentials. Stage 2 — Profiler (D1YrHRTg.bin variants): The profiler registers the host with the command-and-control (C2) server and collects a comprehensive system inventory using sysctl and native macOS tools: hostname, UUID, CPU model, boot time, OS version, running processes, network configuration, installed browser extensions (Chrome, Firefox, Safari, Brave, Opera, Vivaldi). Some profiler instances were observed entering infinite loops, causing resource exhaustion — a noted operational security weakness. Stage 3 — Persistence (minst2.bin): The persistence module creates a folder named 'Antivirus Service,' drops a binary disguised as OneDrive, and installs a LaunchAgent plist (com.onedrive.launcher.plist) to ensure re-execution at every user login. Stage 4 — Stealer (macrasv2): The stealer harvests browser credentials and session cookies from SQLite databases, macOS Keychain entries, SSH keys, and SaaS platform access tokens. Data is archived into a file named user_ext.zip and exfiltrated via the Telegram Bot API, a trusted communication channel that blends into normal corporate traffic. C2 infrastructure communicates over non-standard ports 8888 and 9999. The Go runtime HTTP client is exposed in network traffic via its default User-Agent string (Go-http-client), which aided researcher identification. A critical OPSEC failure was identified: operators inadvertently exposed their Telegram bot token, enabling third parties to read exfiltrated messages and identify operator infrastructure. Researchers also observed exposed WinRM, RDP, and Chrome Remote Desktop services on attacker-controlled infrastructure.","heading":"Malware Architecture and Technical Analysis","severity":"critical","sources":[{"credibility":2,"name":"ANY.RUN Blog: Lazarus Mach-O Man Malware — What CISOs Need to Know","type":"research","url":"https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/"},{"credibility":2,"name":"GBHackers: Lazarus Targets macOS Users With Mach-O Man Malware Kit","type":"news_article","url":"https://gbhackers.com/lazarus-targets-macos-users/amp/"},{"credibility":2,"name":"CyberSecurityNews: Lazarus Hackers Attacking macOS Users With Mach-O Man Malware Kit","type":"news_article","url":"https://cybersecuritynews.com/mach-o-man-macos-malware-lazarus/"},{"credibility":2,"name":"Cryptopolitan: Lazarus Group targets crypto, high-value execs with Mach-O Man","type":"news_article","url":"https://www.cryptopolitan.com/lazarus-group-malware-kit-macos-crypto-execs/"}]},{"content":"The following technical indicators were published by the Bitso Quetzal Team and ANY.RUN as part of the April 2026 disclosure. Network indicators: IP addresses 172.86.113.102 and 144.172.114.220 were identified as active C2 infrastructure. Domains update-teams.live and livemicrosft.com (note the deliberate typosquat of 'microsoft') were used in campaign delivery infrastructure. C2 communication occurs over TCP ports 8888 and 9999. HTTP requests from infected hosts use the Go-http-client User-Agent string. File indicators (SHA-256): teamsSDK.bin — 871d8f92b008a75607c9f1feb4922b9a02ac7bd2ed61b71ca752a5bed5448bf3; macrasv2 — 85bed283ba95d40d99e79437e6a3161336c94ec0acbc0cd38599d0fc9b2e393c. Behavioral indicators: suspicious invocation of curl, Base64, gunzip, osascript, and dscl utilities in sequence from the Terminal; creation of a LaunchAgent at ~/Library/LaunchAgents/com.onedrive.launcher.plist; creation of an 'Antivirus Service' directory; outbound Telegram Bot API connections from macOS hosts; repeated sysctl queries in rapid succession; unauthorized access to Keychain items, browser credential stores, and SSH key directories.","heading":"Indicators of Compromise","severity":"high","sources":[{"credibility":2,"name":"ANY.RUN Blog: Lazarus Mach-O Man Malware — What CISOs Need to Know","type":"research","url":"https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/"},{"credibility":2,"name":"SOC Prime: Mach-O Man Malware Hits Crypto Firms via Telegram","type":"research","url":"https://socprime.com/active-threats/north-koreas-safari-campaign-delivers-rats/"}]},{"content":"The campaign's documented targets are cryptocurrency developers, fintech executives, and high-value enterprise decision-makers who operate primarily on macOS systems. The selection of macOS as the delivery platform reflects a deliberate operational choice: organizations in the crypto and fintech sectors have disproportionately high macOS adoption among engineering and executive teams, and macOS endpoints have historically been subject to less rigorous endpoint detection and response (EDR) coverage relative to Windows environments. Attackers specifically sought access to internal tools, cloud dashboards, crypto wallet seed material, and SaaS session tokens that would enable lateral movement from compromised individual machines into organizational infrastructure. The social engineering pretext — a plausible business meeting invitation from an apparently known contact — is calibrated to the workflow patterns of founders, developers, and senior operators in the crypto space who routinely conduct calls with external parties over Zoom and Teams.","heading":"Target Profile","severity":"high","sources":[{"credibility":2,"name":"Cryptopolitan: Lazarus Group targets crypto, high-value execs with Mach-O Man","type":"news_article","url":"https://www.cryptopolitan.com/lazarus-group-malware-kit-macos-crypto-execs/"},{"credibility":2,"name":"BanklessTimes: Lazarus Unleashes Mach-O Man macOS Malware on Crypto and Fintech","type":"news_article","url":"https://www.banklesstimes.com/articles/2026/04/22/lazarus-unleashes-mach-o-man-macos-malware-on-crypto-and-fintech/"},{"credibility":2,"name":"CyberSecurityNews: Lazarus Hackers Attacking macOS Users With Mach-O Man Malware Kit","type":"news_article","url":"https://cybersecuritynews.com/mach-o-man-macos-malware-lazarus/"}]},{"content":"CertiK researcher Natalie Newson stated that in the two weeks preceding the April 22, 2026 disclosure, Lazarus-attributed attackers siphoned more than $500 million through Drift Protocol and KelpDAO exploits conducted in the same operational window as the Mach-O Man campaign. Drift Protocol was compromised on approximately April 1, 2026, for a reported $285 million. KelpDAO suffered a $290–$292 million breach on April 18, 2026, attributed to Lazarus by LayerZero and confirmed by Chainalysis; the KelpDAO attack targeted off-chain infrastructure (internal RPC nodes) rather than smart contract vulnerabilities, manipulating a verification network to authorize a phantom token burn event. The combined April 2026 theft is reported by multiple sources as approximately $578 million across 18 days. Separately, Chainalysis and TRM Labs data cited across multiple 2026 reports places cumulative Lazarus-attributed cryptocurrency theft since 2017 in excess of $6–$7 billion, with North Korean actors alleged to be responsible for 76% of all global crypto hack losses in the first four months of 2026. The direct financial impact specifically attributable to the Mach-O Man macOS malware — as distinct from simultaneous exchange-level exploits — has not been quantified in publicly available reporting as of the disclosure date.","heading":"Financial Damages and Concurrent Attacks","severity":"critical","sources":[{"credibility":2,"name":"CoinDesk: Lazarus Group Mach-O Man attack — CertiK","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/22/lazarus-group-has-become-especially-dangerous-with-new-mach-o-man-attack-certik"},{"credibility":2,"name":"Bleeping Computer: KelpDAO suffers $290 million heist tied to Lazarus hackers","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/kelpdao-suffers-290-million-heist-tied-to-lazarus-hackers/"},{"credibility":2,"name":"Chainalysis: Inside the KelpDAO Bridge Exploit","type":"research","url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"credibility":1,"name":"UPI: North Korean hackers tied to $290M crypto heist","type":"news_article","url":"https://www.upi.com/Top_News/World-News/2026/04/22/KelpDAO-LayerZero-North-Korea-crypto-hack-theft-Lazarus-Group/6151776848419/"},{"credibility":3,"name":"SpotedCrypto: Lazarus Group Stole $578M in 18 Days","type":"news_article","url":"https://www.spotedcrypto.com/april-2026-crypto-hacks-lazarus-defi-crisis/"}]},{"content":"The Mach-O Man kit incorporates several evasion capabilities that complicate post-incident forensic analysis. The malware is reported to self-delete after execution, removing key components before the victim may become aware of a compromise. The use of Go compilation introduces non-standard binary signatures that may evade conventional signature-based antivirus detection. Ad-hoc code signatures applied via the macOS codesign utility allow the initial payload to pass superficial legitimacy checks without a valid Apple Developer certificate. Exfiltration via the Telegram Bot API routes stolen data through a globally trusted and widely allowlisted communication service, bypassing network-layer data-loss-prevention controls that do not perform deep inspection of Telegram traffic. The campaign's initial access relies entirely on user execution — a technique that sidesteps exploit-based detection mechanisms and shifts the forensic question from 'what exploited this system' to 'which user ran this command.' Collectively, these characteristics render the malware substantially harder to detect via standard endpoint tooling than prior Lazarus macOS tooling such as RustBucket.","heading":"Evasion, Self-Deletion, and Detection Difficulty","severity":"high","sources":[{"credibility":2,"name":"ANY.RUN Blog: Lazarus Mach-O Man Malware — What CISOs Need to Know","type":"research","url":"https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/"},{"credibility":2,"name":"Bitcoin News: Mach-O Man Malware Steals macOS Keychain Data in Lazarus Group Crypto Campaign","type":"news_article","url":"https://news.bitcoin.com/mach-o-man-malware-steals-macos-keychain-data-in-lazarus-group-crypto-campaign/"}]},{"content":"Despite its operational sophistication, the campaign contained notable OPSEC failures. Researchers identified that operators exposed their Telegram bot token in the malware's exfiltration pipeline, allowing third parties to read messages sent to and from the bot, send messages on the bot's behalf, and enumerate operator activity — substantially aiding attribution and potential takedown efforts. Infrastructure scanning revealed exposed WinRM, RDP, and Chrome Remote Desktop services on attacker-controlled servers, suggesting the C2 nodes were themselves accessible via remote management interfaces. Some profiler module variants were found to contain infinite loops, causing excessive CPU and memory usage on infected hosts — a behavioral anomaly that could flag the infection to observant users or monitoring tools. The use of the default Go-http-client User-Agent in C2 communications is a recognizable signature that network-layer detection tools can use as a detection signal.","heading":"Operational Security Failures and Researcher Counter-Intelligence","severity":"medium","sources":[{"credibility":2,"name":"ANY.RUN Blog: Lazarus Mach-O Man Malware — What CISOs Need to Know","type":"research","url":"https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/"},{"credibility":2,"name":"Cybernews: Lazarus macOS malware foiled by C2 exploit","type":"news_article","url":"https://cybernews.com/security/north-korean-hackers-new-malware-foiled-by-researcher/"}]},{"content":"Security researchers noted that the Mach-O Man kit's modular architecture had, by the time of disclosure, already been adopted by other cybercriminal groups beyond Lazarus itself — a pattern consistent with prior Lazarus tooling that has historically diffused into broader criminal ecosystems. A related macOS stealer campaign, ClickLock Stealer, was reported by Group-IB Threat Intelligence on June 9, 2026, distributed via ClickFix phishing pages, with operations targeting at least 100 victims across 33 countries since May 2026. While Group-IB attributed ClickLock Stealer as a distinct tool, the overlap in delivery mechanism (ClickFix), target profile (crypto and fintech), and platform (macOS) suggests meaningful operational convergence with or adaptation from the Mach-O Man campaign. The Lazarus Mach-O Man campaign is assessed to be part of a sustained, institutionally resourced effort by North Korea to fund state activities through cryptocurrency theft, rather than an isolated intrusion.","heading":"Broader Campaign Context and Secondary Adoption","severity":"high","sources":[{"credibility":2,"name":"CoinDesk: Lazarus Group Mach-O Man attack — CertiK","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/22/lazarus-group-has-become-especially-dangerous-with-new-mach-o-man-attack-certik"},{"credibility":2,"name":"RH-ISAC: New ClickLock Stealer macOS Malware Spread via ClickFix Campaign","type":"research","url":"https://rhisac.org/threat-intelligence/new-clicklock-stealer-macos-malware-spread-via-clickfix-campaign/"},{"credibility":2,"name":"Sanctions.io: The Lazarus Group and DPRK Crypto Theft in 2026","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"}]},{"content":"Security researchers and vendors have published the following detection and mitigation recommendations for the Mach-O Man campaign. Detection: Monitor macOS Terminal for suspicious sequential invocation of curl, base64 decoding, gunzip, osascript, and dscl. Audit ~/Library/LaunchAgents/ for unexpected plist files, particularly com.onedrive.launcher.plist or entries referencing 'Antivirus Service.' Flag outbound Telegram Bot API (api.telegram.org) connections originating from macOS hosts in corporate environments where Telegram is not an approved application. Block or alert on network connections to 172.86.113.102, 144.172.114.220, update-teams.live, and livemicrosft.com. Flag HTTP traffic using Go-http-client User-Agent strings on enterprise networks. Monitor sysctl invocations in rapid succession as a behavioral indicator of profiling activity. Prevention: Enforce macOS application allow-listing to block unsigned or ad-hoc-signed binaries. Apply enterprise Gatekeeper policies that require notarization. Disable user ability to run arbitrary Terminal commands on production macOS endpoints. Conduct social engineering awareness training emphasizing that legitimate video conferencing platforms do not instruct users to execute Terminal commands. Implement phishing-resistant MFA across SaaS and cloud platforms to limit the downstream impact of stolen session tokens. Use a secrets manager or hardware security key for crypto wallet access rather than macOS Keychain alone.","heading":"Detection and Mitigation Guidance","severity":"medium","sources":[{"credibility":2,"name":"ANY.RUN Blog: Lazarus Mach-O Man Malware — What CISOs Need to Know","type":"research","url":"https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/"},{"credibility":2,"name":"RH-ISAC: ClickFix Campaign Uses Fake macOS Utilities to Deliver Infostealers","type":"research","url":"https://rhisac.org/threat-intelligence/clickfix-campaign-uses-fake-macos-utilities-to-deliver-infostealers/"}]},{"content":"Lazarus Group is listed on the US Treasury OFAC Specially Designated Nationals list and is subject to North Korea Sanctions Regulations. Any entity that provides material support, transfers funds, goods, or services to or from Lazarus Group — including inadvertently through compromised wallets or mixing services that later co-mingle Lazarus-attributed funds — may face secondary sanctions risk. The US Department of Justice and FBI have previously indicted multiple North Korean nationals associated with Lazarus Group operations, including the 2021 indictment of three DPRK nationals for theft of $1.3 billion in cryptocurrency. Blockchain analytics firms including Chainalysis and Elliptic have published on-chain tracing of Lazarus-attributed fund flows, which typically involve rapid cross-chain bridging, mixing via Tornado Cash and similar protocols, and conversion to fiat through OTC desks in Southeast Asia. Exchanges receiving Lazarus-linked funds may be required to freeze assets under OFAC compliance obligations.","heading":"Regulatory and Sanctions Context","severity":"critical","sources":[{"credibility":1,"name":"OFAC Treasury SDN Designation (April 2022)","type":"regulatory","url":"https://ofac.treasury.gov/recent-actions/20220422"},{"credibility":1,"name":"US Treasury Press Release on DPRK sanctions (2019)","type":"regulatory","url":"https://home.treasury.gov/news/press-releases/sm774"},{"credibility":2,"name":"Sanctions.io: The Lazarus Group and DPRK Crypto Theft in 2026","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"}]}],"sources_used":[{"credibility":2,"name":"CoinDesk: North Korean-backed hackers roll out new attack vector targeting crypto executives and firms","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/22/lazarus-group-has-become-especially-dangerous-with-new-mach-o-man-attack-certik"},{"credibility":2,"name":"ANY.RUN Blog: Lazarus Mach-O Man Malware — What CISOs Need to Know","type":"research","url":"https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/"},{"credibility":2,"name":"Bitso Quetzal Team (Mauro Eldritch) — Substack","type":"research","url":"https://quetzal.bitso.com/"},{"credibility":2,"name":"GBHackers: Lazarus Targets macOS Users With New Mach-O Man Malware Kit","type":"news_article","url":"https://gbhackers.com/lazarus-targets-macos-users/amp/"},{"credibility":2,"name":"CyberSecurityNews: Lazarus Hackers Attacking macOS Users With Mach-O Man Malware Kit","type":"news_article","url":"https://cybersecuritynews.com/mach-o-man-macos-malware-lazarus/"},{"credibility":2,"name":"Dark Reading: North Korea's Lazarus Targets macOS Users via ClickFix","type":"news_article","url":"https://www.darkreading.com/threat-intelligence/north-koreas-lazarus-targets-macos-users-clickfix"},{"credibility":2,"name":"Cryptopolitan: Lazarus Group targets crypto, high-value execs with Mach-O Man macOS malware kit","type":"news_article","url":"https://www.cryptopolitan.com/lazarus-group-malware-kit-macos-crypto-execs/"},{"credibility":2,"name":"Bitcoin News: Mach-O Man Malware Steals macOS Keychain Data in Lazarus Group Crypto Campaign","type":"news_article","url":"https://news.bitcoin.com/mach-o-man-malware-steals-macos-keychain-data-in-lazarus-group-crypto-campaign/"},{"credibility":2,"name":"BanklessTimes: Lazarus Unleashes Mach-O Man macOS Malware on Crypto and Fintech","type":"news_article","url":"https://www.banklesstimes.com/articles/2026/04/22/lazarus-unleashes-mach-o-man-macos-malware-on-crypto-and-fintech/"},{"credibility":2,"name":"Bleeping Computer: KelpDAO suffers $290 million heist tied to Lazarus hackers","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/kelpdao-suffers-290-million-heist-tied-to-lazarus-hackers/"},{"credibility":2,"name":"Chainalysis: Inside the KelpDAO Bridge Exploit","type":"research","url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"credibility":1,"name":"UPI: North Korean hackers tied to $290M crypto heist","type":"news_article","url":"https://www.upi.com/Top_News/World-News/2026/04/22/KelpDAO-LayerZero-North-Korea-crypto-hack-theft-Lazarus-Group/6151776848419/"},{"credibility":1,"name":"MITRE ATT&CK: Lazarus Group (G0032)","type":"research","url":"https://attack.mitre.org/groups/G0032/"},{"credibility":1,"name":"OpenSanctions: Lazarus Group SDN listing","type":"regulatory","url":"https://www.opensanctions.org/entities/NK-Xv8CnM8sgddxx7QenotGtb/"},{"credibility":1,"name":"OFAC Treasury: Recent SDN Actions (April 2022)","type":"regulatory","url":"https://ofac.treasury.gov/recent-actions/20220422"},{"credibility":2,"name":"Sanctions.io: The Lazarus Group and DPRK Crypto Theft in 2026","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"},{"credibility":2,"name":"RH-ISAC: ClickFix Campaign Uses Fake macOS Utilities to Deliver Infostealers","type":"research","url":"https://rhisac.org/threat-intelligence/clickfix-campaign-uses-fake-macos-utilities-to-deliver-infostealers/"},{"credibility":2,"name":"RH-ISAC: New ClickLock Stealer macOS Malware Spread via ClickFix Campaign","type":"research","url":"https://rhisac.org/threat-intelligence/new-clicklock-stealer-macos-malware-spread-via-clickfix-campaign/"},{"credibility":2,"name":"SOC Prime: Mach-O Man Malware Hits Crypto Firms via Telegram","type":"research","url":"https://socprime.com/active-threats/north-koreas-safari-campaign-delivers-rats/"},{"credibility":2,"name":"Cybernews: Lazarus macOS malware foiled by C2 exploit","type":"news_article","url":"https://cybernews.com/security/north-korean-hackers-new-malware-foiled-by-researcher/"},{"credibility":2,"name":"BeInCrypto: LayerZero Ties KelpDAO Exploit to Lazarus Subgroup TraderTraitor","type":"news_article","url":"https://beincrypto.com/layerzero-kelpdao-hack-lazarus-north-korea/"},{"credibility":2,"name":"Crypto.news: North Korea's Lazarus Group targets crypto execs with new macOS malware","type":"news_article","url":"https://crypto.news/north-koreas-lazarus-group-targets-crypto-execs-with-new-macos-malware/"}],"summary":"The Lazarus Group Mach-O Man campaign is a state-sponsored macOS malware operation publicly disclosed in April 2026, attributed to North Korea's Reconnaissance General Bureau via the Chollima operational unit. The campaign delivers a modular, Go-compiled malware kit through ClickFix social engineering — fake video-conference invitations distributed over Telegram — targeting cryptocurrency developers, fintech executives, and high-value enterprise users running Apple hardware. Researchers at Bitso's Quetzal Team and the ANY.RUN sandbox platform identified four distinct attack stages culminating in macOS Keychain theft, browser credential harvesting, and exfiltration via the Telegram Bot API.","timeline":[{"date":"2022-04-14","event":"OFAC places Lazarus Group on the Specially Designated Nationals (SDN) list under North Korea Sanctions Regulations section 510.214.","source":"US Treasury OFAC","source_url":"https://ofac.treasury.gov/recent-actions/20220422"},{"date":"2026-04-01","event":"Drift Protocol suffers an alleged $285 million exploit attributed to the Lazarus Group's TraderTraitor sub-unit, occurring in the same operational window as the Mach-O Man campaign.","source":"SpotedCrypto / Wasteland Intel","source_url":"https://www.spotedcrypto.com/april-2026-crypto-hacks-lazarus-defi-crisis/"},{"date":"2026-04-18","event":"KelpDAO suffers a $290–$292 million bridge exploit attributed to Lazarus Group / TraderTraitor by LayerZero and Chainalysis. The attack targeted off-chain RPC infrastructure rather than smart contracts.","source":"Bleeping Computer / Chainalysis","source_url":"https://www.bleepingcomputer.com/news/security/kelpdao-suffers-290-million-heist-tied-to-lazarus-hackers/"},{"date":"2026-04-21","event":"Bitso Quetzal Team researcher Mauro Eldritch, collaborating with ANY.RUN sandbox, publicly discloses the Mach-O Man macOS malware kit and the broader 'North Korea's Safari' campaign cluster.","source":"ANY.RUN Blog","source_url":"https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/"},{"date":"2026-04-22","event":"CertiK analyst Natalie Newson and CoinDesk publish findings connecting the Mach-O Man kit to the Chollima unit of Lazarus Group. CertiK states that over $500 million was siphoned by Lazarus across Drift and KelpDAO in the preceding two weeks.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/04/22/lazarus-group-has-become-especially-dangerous-with-new-mach-o-man-attack-certik"},{"date":"2026-04-22","event":"Multiple security outlets — CyberSecurityNews, GBHackers, Dark Reading, Cryptopolitan, Bitcoin News, and BanklessTimes — independently publish coverage of the Mach-O Man campaign with technical indicators.","source":"CyberSecurityNews / Dark Reading","source_url":"https://cybersecuritynews.com/mach-o-man-macos-malware-lazarus/"},{"date":"2026-06-09","event":"Group-IB Threat Intelligence reports ClickLock Stealer, a related modular macOS stealer distributed via ClickFix phishing pages, targeting 100+ victims across 33 countries — indicating diffusion of Mach-O Man-style techniques into broader criminal activity.","source":"RH-ISAC","source_url":"https://rhisac.org/threat-intelligence/new-clicklock-stealer-macos-malware-spread-via-clickfix-campaign/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 4bdaa0ee-0a30-4cc9-a492-81a44c197074
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.