New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses
ID: 02cbbf92-b44a-5697-ac47-43820c23d3cd
STIX ID: report--02cbbf92-b44a-5697-ac47-43820c23d3cd
Feed Name: ANY.RUN's Cybersecurity Blog
## Executive Summary The report analyzes an active Lazarus Group campaign delivering a native Go-based macOS malware kit dubbed "Mach-O Man" via Telegram-based meeting lures (ClickFix), which tricks users into executing terminal commands to install a multi-stage infection (stager → profiler → persistence → stealer) that harvests browser credentials, macOS Keychain items, and system data and exfiltrates it over Telegram; the analysis includes behavioral details, IOCs (IPs, domains, file hashes, persistence artifacts), ATT&CK mappings, and remediation/detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
