logo

Lazarus Hackers Attacking macOS Users With ‘Mach-O Man’ Malware Kit

ID: 9248661e-ab61-5a3b-95b5-e093ac6ee9d7

STIX ID: report--9248661e-ab61-5a3b-95b5-e093ac6ee9d7

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-04-29

Date Updated: 2026-05-08

Author: Balaji N

...
...

Mach-O Man is a Go-compiled, native Mach-O macOS malware kit attributed to Lazarus (Chollima) that targets fintech, crypto developers, and high-value enterprise users via Telegram "ClickFix" lures directing victims to fake conferencing sites and convincing them to run a terminal command. The kit unfolds in four stages—teamsSDK.bin (stager), profiler (system inventory and C2 registration), minst2.bin (persistence via a fake OneDrive LaunchAgent), and macrasv2 (stealer that exfiltrates browser data and macOS Keychain via Telegram)—and contains identifiable IOCs (domains, filenames, Telegram bot token) and operator OPSEC errors that aid detection and takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.