Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Hyperliquid growth driven by leveraged degeneracy, trade sharing

    April 23, 2026

    Sam Bankman-Fried drops new trial bid, seeks new judge

    April 23, 2026

    DeFi security researcher implicated in $50M Radiant Capital hack

    April 23, 2026
    Facebook X (Twitter) Instagram
    Ai Crypto TimesAi Crypto Times
    • Altcoins
      • Bitcoin
      • Coinbase
      • Litecoin
    • Blockchain
    • Crypto
    • Ethereum
    • Lithosphere News Releases
    X (Twitter) Instagram YouTube LinkedIn
    Ai Crypto TimesAi Crypto Times
    Home » Lazarus Group Uses Fake Meeting Hack

    Lazarus Group Uses Fake Meeting Hack

    Isabella TaylorBy Isabella TaylorApril 23, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    North Korea’s Lazarus Group has launched a new macOS malware campaign called Mach-O Man that uses fake online meeting invitations to trick crypto and fintech executives into executing malicious commands on their own devices, according to blockchain security firm CertiK.

    Summary

    • Lazarus Group’s new Mach-O Man campaign uses fake meeting invites to lure executives into pasting malicious terminal commands on their Macs.
    • The malware auto-deletes after execution, making the breach nearly impossible to detect through standard forensic methods.
    • CertiK links the same Lazarus push to over $500 million stolen from DeFi platforms Drift and KelpDAO in the past two weeks.

    North Korea’s Lazarus Group is running a new campaign dubbed Mach-O Man that targets executives at crypto, fintech, and other high-value firms by disguising malware delivery as a routine technical fix during a fake business meeting, according to CertiK senior blockchain security researcher Natalie Newson. The campaign was disclosed on April 22 and represents one of the group’s most operationally sophisticated social engineering methods to date.

    Lazarus Group Crypto Hack Hides Behind Routine Business Communications

    The attack chain begins with an urgent-looking meeting invitation sent over Telegram, impersonating a Zoom, Microsoft Teams, or Google Meet call. The link leads to a convincing but fake website that tells the victim to paste a single command into their Mac terminal to resolve an apparent connection issue, a technique CertiK identifies as ClickFix. Once executed, the command installs a modular malware kit built from native Mach-O binaries tailored for Apple environments, which profiles the host, establishes persistence, and exfiltrates credentials and browser data through a Telegram-based command-and-control channel. Critically, the toolkit auto-deletes after completing its task, making detection and forensic analysis extremely difficult. “These fake verification steps guide victims through keyboard shortcuts that run a harmful command,” CertiK’s Newson told CoinDesk. “The page looks real, the instructions seem normal, and the victim initiates the action themselves, which is why traditional security controls often miss it.”

    Why This Attack Is Harder to Catch Than Standard Phishing

    Unlike traditional phishing attacks that rely on urgency cues or suspicious sender addresses, the Mach-O Man campaign is designed to look entirely routine at the moment of delivery. Executives in crypto and fintech routinely receive cold outreach from investors, researchers, and business partners, making the fake meeting invitation format a credible lure in a way that generalized phishing often is not. CertiK’s analysis notes that the Mach-O Man framework is tied to Lazarus’ Famous Chollima unit and distributed through compromised Telegram accounts specifically targeting high-value organizations in the digital asset space. Most victims will not realize they have been compromised until well after the malware has erased itself. “They likely don’t know it yet,” Newson said. “If they do, they probably can’t identify which variant affected them.”

    The Scale of the Lazarus Threat to Crypto in 2026

    CertiK has linked the Mach-O Man campaign to a broader Lazarus offensive that has siphoned more than $500 million from DeFi platforms Drift and KelpDAO in under two weeks, adding to a cumulative theft total estimated at $6.7 billion since 2017. The United Nations has previously estimated that North Korean hackers have stolen several billion dollars in digital assets to fund the country’s weapons programs. “What makes Lazarus especially dangerous right now is their activity level,” Newson said. “This isn’t random hacking. It’s a state-directed financial operation running at a scale and speed typical of institutions.” CertiK is advising crypto professionals to independently verify all meeting requests through a separate channel before clicking any link or downloading any attachment from an unsolicited invitation.

    CertiK has shared indicators of compromise tied to the Mach-O Man campaign with the broader security community to support detection and defense efforts across the industry.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Isabella Taylor

    Related Posts

    Sam Bankman-Fried drops new trial bid, seeks new judge

    April 23, 2026

    Iran Seizes Ships in Strait of Hormuz

    April 23, 2026

    stop taxing every coffee and fix staking rules

    April 23, 2026

    Comments are closed.

    Don't Miss

    Hyperliquid growth driven by leveraged degeneracy, trade sharing

    Coinbase April 23, 2026

    Hyperliquid, a leveraged crypto exchange, has popularized copytrading and leaderboard-based trading contests to gain market…

    Sam Bankman-Fried drops new trial bid, seeks new judge

    April 23, 2026

    DeFi security researcher implicated in $50M Radiant Capital hack

    April 23, 2026

    Lithic Enables Deterministic Control Over AI Execution in Smart Contracts

    April 23, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Our Picks

    Lithic Enables Deterministic Control Over AI Execution in Smart Contracts

    April 23, 2026

    Lithosphere Establishes Cross-Chain Execution Model for Intelligent dApps

    April 22, 2026

    Lithosphere Introduces Decentralized Naming and Routing for Web4 Infrastructure

    April 21, 2026

    Lithosphere Reduces Blockchain Fragmentation Through MultX Interoperability Engine

    April 20, 2026

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    • Popular
    • Recent
    • Top Reviews

    Why FLOW price is up over 50% today after Upbit and Bithumb delisting announcement

    March 14, 2026

    KaJ Labs Unveils Lithic Developer Stack for AI Applications, Games, and Enterprise Systems

    March 14, 2026

    Ethereum price prediction: $2,500 in focus as OI spike amid Vitalik’s calls for scaling

    March 14, 2026

    Hyperliquid growth driven by leveraged degeneracy, trade sharing

    April 23, 2026

    Sam Bankman-Fried drops new trial bid, seeks new judge

    April 23, 2026

    DeFi security researcher implicated in $50M Radiant Capital hack

    April 23, 2026
    Latest Galleries
    [latest_gallery cat="all" number="5" type="slider"]
    Latest Reviews
    Demo
    Top Posts

    KaJ Labs Unveils Ecosystem Alignment Strategy to Strengthen AI and Web3 Integration

    March 14, 20263 Views

    KaJ Labs Unveils Lithic Developer Stack for AI Applications, Games, and Enterprise Systems

    March 14, 20263 Views

    Lithic Introduces zk-Verifiable AI Execution Standard (LEP100-5)

    March 17, 20262 Views

    Lithosphere Introduces LEP100-14 to Enable Coordinated AI Systems Across Decentralized Networks

    April 14, 20261 Views
    Don't Miss

    Hyperliquid growth driven by leveraged degeneracy, trade sharing

    Coinbase April 23, 2026

    Hyperliquid, a leveraged crypto exchange, has popularized copytrading and leaderboard-based trading contests to gain market…

    Sam Bankman-Fried drops new trial bid, seeks new judge

    April 23, 2026

    DeFi security researcher implicated in $50M Radiant Capital hack

    April 23, 2026

    Lithic Enables Deterministic Control Over AI Execution in Smart Contracts

    April 23, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    Top Posts

    Anthropic revenue just hit a $30 billion run rate

    April 9, 20266 Views

    Trillion Dollar Security Day at Devconnect

    April 8, 20265 Views

    Gate brings F1 Red Bull spectacle to Hong Kong waterfront for 13th anniversary

    April 16, 20264 Views

    AI news Perplexity jumps 50% after one big change

    April 10, 20264 Views
    Don't Miss

    Hyperliquid growth driven by leveraged degeneracy, trade sharing

    Coinbase April 23, 2026

    Hyperliquid, a leveraged crypto exchange, has popularized copytrading and leaderboard-based trading contests to gain market…

    Sam Bankman-Fried drops new trial bid, seeks new judge

    April 23, 2026

    DeFi security researcher implicated in $50M Radiant Capital hack

    April 23, 2026

    Lithic Enables Deterministic Control Over AI Execution in Smart Contracts

    April 23, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Hyperliquid growth driven by leveraged degeneracy, trade sharing

    April 23, 2026

    Sam Bankman-Fried drops new trial bid, seeks new judge

    April 23, 2026

    DeFi security researcher implicated in $50M Radiant Capital hack

    April 23, 2026
    Recent Posts
    • Hyperliquid growth driven by leveraged degeneracy, trade sharing
    • Sam Bankman-Fried drops new trial bid, seeks new judge
    • DeFi security researcher implicated in $50M Radiant Capital hack
    • Lithic Enables Deterministic Control Over AI Execution in Smart Contracts
    • Iran Seizes Ships in Strait of Hormuz
    © 2026 - 2026

    Type above and press Enter to search. Press Esc to cancel.