Lazarus Group Mach-O Man macOS Campaign — 2026
Summary
The Lazarus Group Mach-O Man campaign is a state-sponsored macOS malware operation publicly disclosed in April 2026, attributed to North Korea's Reconnaissance General Bureau via the Chollima operational unit. The campaign delivers a modular, Go-compiled malware kit through ClickFix social engineering — fake video-conference invitations distributed over Telegram — targeting cryptocurrency developers, fintech executives, and high-value enterprise users running Apple hardware. Researchers at Bitso's Quetzal Team and the ANY.RUN sandbox platform identified four distinct attack stages culminating in macOS Keychain theft, browser credential harvesting, and exfiltration via the Telegram Bot API.
Connected Entities
1 entities · 10 linked investigationsTimeline(7 events)
2022-04-14
OFAC places Lazarus Group on the Specially Designated Nationals (SDN) list under North Korea Sanctions Regulations section 510.214.
US Treasury OFAC2026-04-01
Drift Protocol suffers an alleged $285 million exploit attributed to the Lazarus Group's TraderTraitor sub-unit, occurring in the same operational window as the Mach-O Man campaign.
SpotedCrypto / Wasteland Intel2026-04-18
KelpDAO suffers a $290–$292 million bridge exploit attributed to Lazarus Group / TraderTraitor by LayerZero and Chainalysis. The attack targeted off-chain RPC infrastructure rather than smart contracts.
Bleeping Computer / Chainalysis2026-04-21
Bitso Quetzal Team researcher Mauro Eldritch, collaborating with ANY.RUN sandbox, publicly discloses the Mach-O Man macOS malware kit and the broader 'North Korea's Safari' campaign cluster.
ANY.RUN Blog2026-04-22
CertiK analyst Natalie Newson and CoinDesk publish findings connecting the Mach-O Man kit to the Chollima unit of Lazarus Group. CertiK states that over $500 million was siphoned by Lazarus across Drift and KelpDAO in the preceding two weeks.
CoinDesk2026-04-22
Multiple security outlets — CyberSecurityNews, GBHackers, Dark Reading, Cryptopolitan, Bitcoin News, and BanklessTimes — independently publish coverage of the Mach-O Man campaign with technical indicators.
CyberSecurityNews / Dark Reading2026-06-09
Group-IB Threat Intelligence reports ClickLock Stealer, a related modular macOS stealer distributed via ClickFix phishing pages, targeting 100+ victims across 33 countries — indicating diffusion of Mach-O Man-style techniques into broader criminal activity.
RH-ISACDecision Log
- #1publish⛓ pending8/7/2026, 12:26:11 PMhash: 97dYL5p7Pbz9MHu5GUBJhuysAbkPnXFFn7tx9uy1w8T4
22 of 22 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/7/2026, 12:26:01 PM
last updated: 8/8/2026, 4:12:20 AM
avoid.net — verified advice for a post-truth world