logo

North Korea's Lazarus Targets macOS Users via ClickFix

ID: b0c0a721-32ca-5594-a509-776aa89a7a35

STIX ID: report--b0c0a721-32ca-5594-a509-776aa89a7a35

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Alexander Culafi

...
...

North Korea's Lazarus Group is running ClickFix attacks that socially engineer victims (fake meeting invites) into running commands or opening files, delivering a macOS malware kit culminating in the 'macrasv2' stealer which gathers browser credentials, cookies, and macOS Keychain data and exfiltrates via Telegram; the report outlines the full attack chain, exposed operational weaknesses, IOCs, and mitigation guidance such as user training and monitoring high-risk command execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.