Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Mach-O Man Malware Steals macOS Keychain Data in Lazarus Group Crypto Campaign – Bitcoin News

CryptoExpert by CryptoExpert
April 22, 2026
in Bitcoin News
0
Mach-O Man Malware Steals macOS Keychain Data in Lazarus Group Crypto Campaign – Bitcoin News
  • Facebook
  • Twitter
  • Pinterest


You might also like

Bitcoin Is Setting Up A Similar Structure To 2017 & 2021, What Happened Last Time?

Bitcoin Could Surge as AI Race and War Fuel Money Printing says Hayes

US Banks Prepare for Tokenization Tipping Point, Moody’s Ratings Finds – Bitcoin News

Key Takeaways:

North Korea’s Lazarus Group deployed Mach-O Man malware targeting macOS users in crypto and fintech roles in April 2026. Bitso’s Quetzal Team confirmed the Go-compiled kit enables credential theft, Keychain access, and data exfiltration via four stages. Security researchers urged firms on April 22, 2026, to block Terminal-based ClickFix lures and audit LaunchAgents for Onedrive masquerading files.

Researchers Expose North Korean macOS Malware Targeting U.S. Crypto and Web3 Firms

Security researchers at Bitso’s Quetzal Team, working alongside the ANY.RUN sandbox platform, publicly disclosed the kit on April 21, 2026, after analyzing a campaign they named “North Korea’s Safari.” The team connected the kit to Lazarus’s recent large-scale crypto thefts, including attacks on KelpDAO and Drift, citing the group’s consistent targeting of high-value macOS users in Web3 and fintech roles.

Mach-O Man is written in Go and compiled as Mach-O binaries, making it native to both Intel and Apple Silicon machines. The kit runs in four distinct stages and is designed to harvest browser credentials, macOS Keychain entries, and crypto account access before deleting traces of itself.

okex

The infection begins with social engineering, not a software exploit. Attackers compromise or impersonate Telegram accounts belonging to colleagues in Web3 and crypto circles. The target receives an urgent meeting invite for Zoom, Microsoft Teams, or Google Meet that links to a convincing fake site, such as update-teams.live or livemicrosft.com.

The fake site displays a simulated connection error and instructs the user to copy and paste a Terminal command to resolve it. This technique, known as Clickfix and adapted here for macOS, leads the user to execute the initial stager file, teamsSDK.bin, via curl. Because the user runs the command manually, macOS Gatekeeper does not block it.

The stager downloads a fake app bundle, applies ad-hoc code signing to make it appear legitimate, and prompts the user for their macOS password. The window shakes on the first two attempts and accepts the credential on the third, a deliberate design choice to build false trust.

From there, the researcher’s report, and other accounts say a profiler binary enumerates the machine’s hostname, UUID, CPU, operating system details, running processes, and browser extensions across Brave, Chrome, Firefox, Safari, Opera, and Vivaldi. Researchers noted the profiler contains a coding bug that creates an infinite loop, causing noticeable CPU spikes that can expose an active infection.

A persistence module then drops a renamed file called Onedrive into a hidden path under a folder labeled “Antivirus Service” and registers a Launchagent called com.onedrive.launcher.plist so it runs automatically at login.

The final stage, a stealer binary labeled macrasv2, collects browser extension data, SQLite credential databases, and Keychain items, compresses them into a zip file, and exfiltrates the package through the Telegram Bot API. Researchers found the Telegram bot token exposed in the binary, which they described as a major operational security failure that could allow defenders to monitor or disrupt the channel.

The Quetzal Team published SHA-256 hashes for all major components, along with network indicators pointing to IP addresses 172.86.113.102 and 144.172.114.220. Security researchers noted the kit has been observed in use by groups beyond Lazarus, suggesting the tooling has been shared or sold within the threat actor ecosystem.

Lazarus, also tracked as Famous Chollima by threat intelligence firms, has been attributed to billions of dollars in cryptocurrency theft over the past several years. The group’s prior macOS tools included Applejeus and Rustbucket. Mach-O Man follows the same target profile while lowering the technical barrier for macOS compromises.

Volo Protocol Loses $3.5 Million in Sui Blockchain Exploit, Blocks WBTC Bridge Attempt

Volo Protocol, a liquid staking and BTCFi platform on the Sui blockchain, confirmed a $3.5 million security exploit this week,…

Read Now

Volo Protocol Loses $3.5 Million in Sui Blockchain Exploit, Blocks WBTC Bridge Attempt

Bitcoin.com News

Volo Protocol Loses $3.5 Million in Sui Blockchain Exploit, Blocks WBTC Bridge Attempt

Volo Protocol, a liquid staking and BTCFi platform on the Sui blockchain, confirmed a $3.5 million security exploit this week,…

Read Now

Volo Protocol Loses $3.5 Million in Sui Blockchain Exploit, Blocks WBTC Bridge Attempt

Bitcoin.com News

Volo Protocol Loses $3.5 Million in Sui Blockchain Exploit, Blocks WBTC Bridge Attempt

Read Now

Volo Protocol, a liquid staking and BTCFi platform on the Sui blockchain, confirmed a $3.5 million security exploit this week,…

Security teams at crypto and fintech firms are advised to audit Launchagents directories, monitor for Onedrive processes running from unusual file paths, and block outbound Telegram Bot API traffic where it is not operationally required. Users should never paste Terminal commands copied from web pages or unsolicited meeting links.

Organizations running macOS fleets in Apple-heavy crypto environments should treat any urgent, unsolicited meeting link as a potential entry point until verified through a separate communication channel.



Source link

  • Facebook
  • Twitter
  • Pinterest
Tags: Bitcoin
CryptoExpert

CryptoExpert

Recommended For You

Bitcoin Is Setting Up A Similar Structure To 2017 & 2021, What Happened Last Time?

by CryptoExpert
May 13, 2026
0
Bitcoin

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Bitcoin’s move back above $80,000 has brought various interesting outlooks in terms of what’s next....

Read more

Bitcoin Could Surge as AI Race and War Fuel Money Printing says Hayes

by CryptoExpert
May 13, 2026
0
Bitcoin Could Surge as AI Race and War Fuel Money Printing says Hayes

The ongoing war in Iran and the race to dominate the AI sector will result in money printing that could benefit the crypto ecosystem and push Bitcoin back...

Read more

US Banks Prepare for Tokenization Tipping Point, Moody’s Ratings Finds – Bitcoin News

by CryptoExpert
May 12, 2026
0
US Banks Prepare for Tokenization Tipping Point, Moody’s Ratings Finds – Bitcoin News

Key TakeawaysMoody’s reports that U.S. banks see a “slow then fast” shift to tokenized assets and digital money as inevitable.DTCC plans to launch limited production trades of tokenized...

Read more

Trump Rejects Iran Peace Proposal — Bitcoin Breaks $82,000

by CryptoExpert
May 12, 2026
0
Bitcoin

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Bitcoin has now climbed nearly 30% since the US-Iran war began on February 28 —...

Read more

Bitcoin Funding Flips Positive, Is $85K Next?

by CryptoExpert
May 12, 2026
0
Bitcoin Funding Flips Positive, Is $85K Next?

Key takeaways:Bitcoin derivatives show limited conviction among pro traders, but ETF flows and Strategy could play a role in the next higher rally. Reduced odds of a peace plan...

Read more
Next Post
Crypto Firms Report Flood of AI-Driven Bug Bounty Submissions

Crypto Firms Report Flood of AI-Driven Bug Bounty Submissions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 79,572.00
ethereum
Ethereum (ETH) $ 2,259.61
tether
Tether (USDT) $ 0.999558
bnb
BNB (BNB) $ 671.27
xrp
XRP (XRP) $ 1.43
usd-coin
USDC (USDC) $ 0.999486
solana
Solana (SOL) $ 90.84
tron
TRON (TRX) $ 0.350105
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?