Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Mach-O Man Malware Steals macOS Keychain Data in Lazarus Group Crypto Campaign – Bitcoin News

CryptoExpert by CryptoExpert
April 22, 2026
in Bitcoin News
0
Mach-O Man Malware Steals macOS Keychain Data in Lazarus Group Crypto Campaign – Bitcoin News
  • Facebook
  • Twitter
  • Pinterest


You might also like

The Top Bitcoin Predictions From Industry Experts Go As High As $500,000

ABTC Energizes More Than 11,000 New Bitcoin Mining Rigs

Ceasefire Drama Escalates—Trump Points Finger At Iran, Bitcoin In Focus

Key Takeaways:

North Korea’s Lazarus Group deployed Mach-O Man malware targeting macOS users in crypto and fintech roles in April 2026. Bitso’s Quetzal Team confirmed the Go-compiled kit enables credential theft, Keychain access, and data exfiltration via four stages. Security researchers urged firms on April 22, 2026, to block Terminal-based ClickFix lures and audit LaunchAgents for Onedrive masquerading files.

Researchers Expose North Korean macOS Malware Targeting U.S. Crypto and Web3 Firms

Security researchers at Bitso’s Quetzal Team, working alongside the ANY.RUN sandbox platform, publicly disclosed the kit on April 21, 2026, after analyzing a campaign they named “North Korea’s Safari.” The team connected the kit to Lazarus’s recent large-scale crypto thefts, including attacks on KelpDAO and Drift, citing the group’s consistent targeting of high-value macOS users in Web3 and fintech roles.

Mach-O Man is written in Go and compiled as Mach-O binaries, making it native to both Intel and Apple Silicon machines. The kit runs in four distinct stages and is designed to harvest browser credentials, macOS Keychain entries, and crypto account access before deleting traces of itself.

okex

The infection begins with social engineering, not a software exploit. Attackers compromise or impersonate Telegram accounts belonging to colleagues in Web3 and crypto circles. The target receives an urgent meeting invite for Zoom, Microsoft Teams, or Google Meet that links to a convincing fake site, such as update-teams.live or livemicrosft.com.

The fake site displays a simulated connection error and instructs the user to copy and paste a Terminal command to resolve it. This technique, known as Clickfix and adapted here for macOS, leads the user to execute the initial stager file, teamsSDK.bin, via curl. Because the user runs the command manually, macOS Gatekeeper does not block it.

The stager downloads a fake app bundle, applies ad-hoc code signing to make it appear legitimate, and prompts the user for their macOS password. The window shakes on the first two attempts and accepts the credential on the third, a deliberate design choice to build false trust.

From there, the researcher’s report, and other accounts say a profiler binary enumerates the machine’s hostname, UUID, CPU, operating system details, running processes, and browser extensions across Brave, Chrome, Firefox, Safari, Opera, and Vivaldi. Researchers noted the profiler contains a coding bug that creates an infinite loop, causing noticeable CPU spikes that can expose an active infection.

A persistence module then drops a renamed file called Onedrive into a hidden path under a folder labeled “Antivirus Service” and registers a Launchagent called com.onedrive.launcher.plist so it runs automatically at login.

The final stage, a stealer binary labeled macrasv2, collects browser extension data, SQLite credential databases, and Keychain items, compresses them into a zip file, and exfiltrates the package through the Telegram Bot API. Researchers found the Telegram bot token exposed in the binary, which they described as a major operational security failure that could allow defenders to monitor or disrupt the channel.

The Quetzal Team published SHA-256 hashes for all major components, along with network indicators pointing to IP addresses 172.86.113.102 and 144.172.114.220. Security researchers noted the kit has been observed in use by groups beyond Lazarus, suggesting the tooling has been shared or sold within the threat actor ecosystem.

Lazarus, also tracked as Famous Chollima by threat intelligence firms, has been attributed to billions of dollars in cryptocurrency theft over the past several years. The group’s prior macOS tools included Applejeus and Rustbucket. Mach-O Man follows the same target profile while lowering the technical barrier for macOS compromises.

Volo Protocol Loses $3.5 Million in Sui Blockchain Exploit, Blocks WBTC Bridge Attempt

Volo Protocol, a liquid staking and BTCFi platform on the Sui blockchain, confirmed a $3.5 million security exploit this week,…

Read Now

Volo Protocol Loses $3.5 Million in Sui Blockchain Exploit, Blocks WBTC Bridge Attempt

Bitcoin.com News

Volo Protocol Loses $3.5 Million in Sui Blockchain Exploit, Blocks WBTC Bridge Attempt

Volo Protocol, a liquid staking and BTCFi platform on the Sui blockchain, confirmed a $3.5 million security exploit this week,…

Read Now

Volo Protocol Loses $3.5 Million in Sui Blockchain Exploit, Blocks WBTC Bridge Attempt

Bitcoin.com News

Volo Protocol Loses $3.5 Million in Sui Blockchain Exploit, Blocks WBTC Bridge Attempt

Read Now

Volo Protocol, a liquid staking and BTCFi platform on the Sui blockchain, confirmed a $3.5 million security exploit this week,…

Security teams at crypto and fintech firms are advised to audit Launchagents directories, monitor for Onedrive processes running from unusual file paths, and block outbound Telegram Bot API traffic where it is not operationally required. Users should never paste Terminal commands copied from web pages or unsolicited meeting links.

Organizations running macOS fleets in Apple-heavy crypto environments should treat any urgent, unsolicited meeting link as a potential entry point until verified through a separate communication channel.



Source link

  • Facebook
  • Twitter
  • Pinterest
Tags: Bitcoin
CryptoExpert

CryptoExpert

Recommended For You

The Top Bitcoin Predictions From Industry Experts Go As High As $500,000

by CryptoExpert
April 23, 2026
0
Bitcoin

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure A compilation shared on X has brought together a string of bullish Bitcoin calls from...

Read more

ABTC Energizes More Than 11,000 New Bitcoin Mining Rigs

by CryptoExpert
April 22, 2026
0
ABTC Energizes More Than 11,000 New Bitcoin Mining Rigs

American Bitcoin (ABTC), a publicly traded mining company co-founded by United States President Donald Trump’s sons, has completed its energization of 11,298 application-specific integrated circuits (ASICs) at its...

Read more

Ceasefire Drama Escalates—Trump Points Finger At Iran, Bitcoin In Focus

by CryptoExpert
April 22, 2026
0
Legal Battle Forces Singapore-based AI firm to Halt Bitcoin Purchases—What Happened?

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Iran’s Foreign Ministry came out swinging on Sunday, accusing the United States of committing war...

Read more

BTC Binance Inflows Drop As Coinbase Activity Rises

by CryptoExpert
April 21, 2026
0
BTC Binance Inflows Drop As Coinbase Activity Rises

Bitcoin (BTC) mid-size wallet inflows to Binance fell to 3,000–4,000 BTC, marking a multi-year low in sell-side activity from this cohort.This coincides with Coinbase recording about 8,500 BTC...

Read more

Tokenized Real-World Asset Market Cap Surges 20x in Three Years, Topping $29 Billion

by CryptoExpert
April 21, 2026
0
Tokenized Real-World Asset Market Cap Surges 20x in Three Years, Topping $29 Billion

Key Takeaways: Tokenized RWA market cap has expanded 20x in three years, reaching $29.27 billion as per RWA.xyz data. Tokenized U.S. Treasuries grew from $380 million in Q1...

Read more
Next Post
Crypto Firms Report Flood of AI-Driven Bug Bounty Submissions

Crypto Firms Report Flood of AI-Driven Bug Bounty Submissions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 78,184.00
ethereum
Ethereum (ETH) $ 2,353.86
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 1.42
bnb
BNB (BNB) $ 637.53
usd-coin
USDC (USDC) $ 0.999668
solana
Solana (SOL) $ 86.03
tron
TRON (TRX) $ 0.327269
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?