logo

New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses

ID: 02cbbf92-b44a-5697-ac47-43820c23d3cd

STIX ID: report--02cbbf92-b44a-5697-ac47-43820c23d3cd

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
85/100

Date Published: 2026-04-21

Date Updated: 2026-04-26

Author: Mauro Eldritch

...
...

## Executive Summary The report analyzes an active Lazarus Group campaign delivering a native Go-based macOS malware kit dubbed "Mach-O Man" via Telegram-based meeting lures (ClickFix), which tricks users into executing terminal commands to install a multi-stage infection (stager → profiler → persistence → stealer) that harvests browser credentials, macOS Keychain items, and system data and exfiltrates it over Telegram; the analysis includes behavioral details, IOCs (IPs, domains, file hashes, persistence artifacts), ATT&CK mappings, and remediation/detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.