TechFlow Logo
Login/ Sign up
ETH Gas
Gwei
Fear
gas
Lazarus Targets macOS: A Fake Zoom Link Attempts to Drain Crypto Executives’ Funds

Lazarus Targets macOS: A Fake Zoom Link Attempts to Drain Crypto Executives’ Funds

2026.04.23
Share

TechFlow Selected TechFlow Selected

techFlow

Lazarus Targets macOS: A Fake Zoom Link Attempts to Drain Crypto Executives’ Funds

Lazarus was the mastermind behind the $1.4 billion Bybit hack in 2025.

2026.04.23 - 07:28:55
黑客
Lazarus was the mastermind behind the $1.4 billion Bybit hack in 2025.

Author: Zoltan Vardai

Compiled by: TechFlow

TechFlow Intro: Security researchers have discovered that the North Korean hacker group Lazarus is deploying a new macOS malware toolkit dubbed “Mach-O Man” to target executives at cryptocurrency firms and traditional financial institutions. The attackers lure victims via fake Zoom and Google Meet meeting links. Once victims execute the provided command, the malware silently runs in the background to steal sensitive data—including browser credentials and Keychain passwords—and exfiltrates it via Telegram. Lazarus was also behind the $1.4 billion Bybit heist in 2025.

Security researchers have linked a newly identified macOS malware campaign to the Lazarus Group—a North Korea–affiliated hacking organization responsible for several of the largest cryptocurrency thefts on record.

Mauro Eldritch, founder of threat intelligence firm BCA Ltd. and an offensive security expert, disclosed this new malware toolkit—named “Mach-O Man”—on Tuesday. It spreads via ClickFix social engineering, targeting both traditional enterprises and cryptocurrency companies.

Attack Flow: Fake Zoom Meeting → Background Malware Installation

The attack works as follows: Victims are lured into joining a spoofed Zoom or Google Meet video call. A webpage then prompts them to execute a command. Once executed, the malware downloads and installs silently in the background—bypassing conventional security controls and triggering no alerts—ultimately granting attackers access to user credentials and corporate system privileges.

In his report published Tuesday (link), Eldritch warned that this campaign could lead to account takeovers, unauthorized infrastructure access, financial losses, and critical data breaches. Lazarus’s targeting scope has now expanded beyond crypto-native companies.

The Lazarus Group is the prime suspect behind multiple historic cryptocurrency heists—including the $1.4 billion breach of the Bybit exchange in 2025, which remains the largest single theft in industry history.

image

Caption: Spoofed Mach-O Man toolkit application interface

Source: ANY.RUN

End Goal: Stealing Everything from Browsers and Keychain

The final stage of the attack chain is a credential stealer designed specifically to extract browser extension data, saved browser credentials, cookies, macOS Keychain entries, and other sensitive information.

image

Caption: Final deployed directory structure of the stealer

Source: ANY.RUN

After collecting the data, the malware packages everything into a ZIP archive and sends it to the attackers via Telegram. Finally, a self-destruct script deletes the entire toolkit using the system’s rm command—bypassing user confirmation and permission checks to force-delete files without leaving traces.

This novel malware toolkit was reconstructed and analyzed by security experts using ANY.RUN’s cloud-based macOS malware sandbox capabilities.

North Korean Hackers’ Attack Surface Continues to Expand

Earlier this April, North Korean hackers used AI-powered social engineering to steal approximately $100,000 from the crypto wallet Zerion, gaining access to logged-in sessions, credentials, and corporate private keys belonging to some team members.

Additionally, CZ recently issued a warning after his security team “SEAL” identified 60 North Korea–linked individuals posing as IT professionals who had infiltrated cryptocurrency firms.

North Korea’s infiltration of the cryptocurrency industry extends far beyond simple “hacking.” From impersonating employees to AI-driven social engineering and custom-built malware, the attack surface continues to widen. macOS users have long been considered relatively secure—but clearly, Lazarus disagrees.

Join TechFlow official community to stay tuned

Add to Favorites
Share to Social Media

Related Articles

2026.04.28

DeFi Security Guide: How to Effectively Defend Against Hacker Attacks in the AI Era?

Cyberattacks will not cease; as AI becomes smarter, attacks will only increase.

DeFi Security Guide: How to Effectively Defend Against Hacker Attacks in the AI Era?
2026.04.23

Exclusive Interview with an Arbitrum Security Council Member: Why Did We Activate the “God Mode” to Freeze $72 Million Stolen by North Korean Hackers?

If freezing North Korean funds could make Circle money, they would certainly do it.

Exclusive Interview with an Arbitrum Security Council Member: Why Did We Activate the “God Mode” to Freeze $72 Million Stolen by North Korean Hackers?
2026.04.23

North Korean Hackers Steal $500 Million in a Single Month, Becoming the Top Threat to Cryptocurrency Security

Drift Protocol and KelpDAO were attacked, suffering losses of approximately $286 million and $290 million, respectively; the attackers targeted peripheral infrastructure of the protocols.

North Korean Hackers Steal $500 Million in a Single Month, Becoming the Top Threat to Cryptocurrency Security
2026.04.21

Reviewing 20 Hacking Incidents: Why Does the Crypto Industry Keep Getting Hacked?

Analyzing 20 cryptocurrency theft cases, dissecting the two attack paths exploited by hackers, and explaining why a vulnerability in one protocol can harm the entire ecosystem.

Reviewing 20 Hacking Incidents: Why Does the Crypto Industry Keep Getting Hacked?
2026.04.19

The Largest DeFi Heist of 2026: After the Hack, the Attacker Briefly Exploited Aave

A Fake Message Scammed $292 Million: Kelp DAO’s Cross-Chain Bridge Drained in 46 Minutes

The Largest DeFi Heist of 2026: After the Hack, the Attacker Briefly Exploited Aave
2026.04.07

Fortune Magazine Reporter: “I Knew North Korean Hackers Were Rampant—Yet I Still Fell for It”

North Korean hackers have targeted cryptocurrency journalists.

Fortune Magazine Reporter: “I Knew North Korean Hackers Were Rampant—Yet I Still Fell for It”
2026.04.07

How North Korean Hackers Continuously Target the Cryptocurrency Industry

North Korea will keep its eyes on the crypto industry for the long term—not because it has much interest in these new concepts, but because the industry is genuinely useful to it.

How North Korean Hackers Continuously Target the Cryptocurrency Industry
2026.03.23

Under the Shadow of Hackers: It’s Not Just Funds That Vanish

Theft is merely the beginning of the crisis. What truly determines whether a project still has a future is the prolonged, slow, and ongoing secondary damage that follows the attack.

Under the Shadow of Hackers: It’s Not Just Funds That Vanish
2025.12.09

The Backside of "Stolen or Scammed" Cryptocurrencies: Why Civil Remedies Frequently Encounter Obstacles?

Discussing the current state and challenges of criminal cases involving cryptocurrencies.

The Backside of "Stolen or Scammed" Cryptocurrencies: Why Civil Remedies Frequently Encounter Obstacles?
2025.11.24

Covert War: North Korean Hackers Have Infiltrated 20% of Crypto Companies

They work efficiently, have long working hours, and never complain.

Covert War: North Korean Hackers Have Infiltrated 20% of Crypto Companies
TechFlow Logo

Navigating Web3 tides with focused insights

Contribute An Articleemail
Media Requestsmsg

Risk Disclosure: This website's content is not investment advice and offers no trading guidance or related services. Per regulations from the PBOC and other authorities, users must be aware of virtual currency risks. Contact us / [email protected] ICP License: 琼ICP备2022009338号