North Korea's Lazarus Group rolls out "MachO Man" macOS malware aimed at crypto and fintech leaders

North Korean hacking outfit Lazarus Group has launched a fresh macOS malware campaign dubbed "MachO Man," setting its sights on executives and organizations in high-value industries including cryptocurrency and fintech, CoinDesk reported. The operation relies on a social-engineering lure known as "ClickFix," which persuades targets to paste commands into the macOS Terminal. Once executed, the attackers can gain footholds across enterprise systems, SaaS platforms, and access pathways to financial resources. Researchers at CertiK describe "MachO Man" as a modular macOS malware toolkit built by Lazarus that is now also being adopted by other cybercriminal groups. The malware can delete itself before victims detect it, complicating attribution and detection. Attackers have already used the playbook by hijacking DeFi project domains and swapping in fake Cloudflare messages to lure users into the scam.