North Korea's Lazarus Targets macOS Users via ClickFix
ID: b0c0a721-32ca-5594-a509-776aa89a7a35
STIX ID: report--b0c0a721-32ca-5594-a509-776aa89a7a35
Feed Name: Dark Reading
Threat Score
North Korea's Lazarus Group is running ClickFix attacks that socially engineer victims (fake meeting invites) into running commands or opening files, delivering a macOS malware kit culminating in the 'macrasv2' stealer which gathers browser credentials, cookies, and macOS Keychain data and exfiltrates via Telegram; the report outlines the full attack chain, exposed operational weaknesses, IOCs, and mitigation guidance such as user training and monitoring high-risk command execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
