logo

Lazarus Targets macOS Users With New “Mach-O Man” Malware Kit

ID: b561ad20-dbd1-546f-90bb-f0af96a24d70

STIX ID: report--b561ad20-dbd1-546f-90bb-f0af96a24d70

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Mayura Kathir

...
...

Lazarus Group is conducting a ClickFix social engineering campaign targeting fintech and crypto organizations by convincing macOS users to paste Terminal commands that deploy a modular Mach-O malware kit. The chain (stagers such as teamsSDK.bin, profilers like D1YrHRTg.bin, and a stealer macrasv2) harvests browser credentials, cookies, and Keychain entries, establishes persistence via LaunchAgents (e.g., minst2.bin disguised as OneDrive/Antivirus Service), and exfiltrates data to C2 — evading many EDRs by abusing native utilities and user-driven execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.