• Advertise with us
  • Pricing
  • Submit News
Instagram Twitter Facebook Telegram Youtube Linkedin
EdaFace Newsfeed
EdaFace Newsfeed
  • News

    Main News

    • Crypto News
    • Bitcoin and BTC
    • Altcoin News
    • Security & Hacks
    • ICO & Token Sales
    • Interviews & Profiles

    Information

    • Press Release
    • Research Report
    • Regulations, Law & Policy
    • Community/Guest Post
    • Events & Conferences
    • Tutorials & Guides

    Market

    • Technical Analysis
    • Price Analysis
    • Cryptocurrency Price Prediction
    • DeFi (Decentralized Finance)
    • Mining & Staking

    Other Categories

    • NFTs & Digital Art
    • Opinion & Editorials
    • Tech Innovations
  • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
More
  • News
  • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
Reading: Lazarus Group’s Mach-O Man attack stole $500 million from crypto executives
Share
Sign In
EdaFace Newsfeed
EdaFace Newsfeed
  • EdaFace Home
  • Edaface News
    • EdaFace News
    • Advertisement
    • Pricing
    • Submit News
  • News
    • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
  • Contact Us
  • EdaFace Home
  • Edaface News
    • EdaFace News
    • Advertisement
    • Pricing
    • Submit News
  • News
    • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
  • Contact Us
EdaFace Newsfeed > Latest News > Security & Hacks > Lazarus Group’s Mach-O Man attack stole $500 million from crypto executives
Security & Hacks

Lazarus Group’s Mach-O Man attack stole $500 million from crypto executives

vitalclick
Last updated: April 22, 2026 2:26 pm
1 day ago
Share
SHARE

Contents
Mach-O Man and targeted sectorsAttack method: ClickFix and social engineering tacticsNew threats to DeFi projects

Lazarus Group, which has recently attracted the attention of those who follow the crypto world closely, is bringing large-scale cyber attacks, formerly identified with the banking sector, to the finance and digital money markets. This cyber group, known to operate in conjunction with the North Korean government, stands out with a total of $6.7 billion in accumulated robberies since 2017. According to recent analysis, Lazarus targeted executives and companies in the fintech and cryptocurrency sectors with the new attack method called Mach-O Man.

Mach-O Man and targeted sectors

Natalie Newson is an expert blockchain security researcher at CertiK and closely examines Lazarus Group’s activities in the crypto and fintech space. Over the last two weeks, the group has managed to withdraw a total of over $500 million in digital assets from the Drift and KelpDAO platforms. In the statement, it was emphasized that the attack wave called Mach-O Man was not a random cyber threat, but an operation carried out officially by North Korea and planned on an institutional scale.

With this new attack method, institutions and senior executives, especially those operating in the field of crypto and finance, are targeted. It is considered that North Korea has turned cryptocurrency theft into a systematic state revenue model. Experts point out that Mach-O Man is used with different variations not only by Lazarus but also by other criminal organizations.

Attack method: ClickFix and social engineering tactics

The most striking feature of the Mach-O Man attack is that it is a modular macOS malware. This malware, developed by Lazarus’ subunit called ‘Chollima’, targets crypto and fintech-oriented applications running on the Apple operating system. Newson states that Mach-O Man was distributed through a social engineering technique called ‘ClickFix’.



In this method, attackers can send urgent meeting invitations to administrators via Telegram. It then redirects victims to a fake website via a link on familiar platforms like Zoom, Microsoft Teams or Google Meet. Victims are informed that there is a connection problem and that they need to paste a specific command into the terminal to fix it. In fact, this command gives attackers direct access to corporate systems and financial resources.

“The page looks real, the instructions are ordinary, and the victims themselves initiate the action, which causes classic security measures to often fail to detect the attack,” Newson said.

New threats to DeFi projects

The Mach-O Man developed by Lazarus causes serious harm at both the institutional and individual levels. DeFi projects in particular are under threat. According to information provided by security threat researcher Vladimir S., attackers took over the domain names of some decentralized finance projects, replaced the websites with fake Cloudflare alerts and demanded commands from visitors.



In these attacks, malicious commands are generally executed under the guise of an “authentication step”. Because the instructions seem realistic, most users or administrators follow the commands without questioning, resulting in full access to the platform’s systems. Malware, on the other hand, deletes itself in a short time and disappears without leaving a trace.

“Most victims are not even aware that they have been attacked. Even if they realize it at the time, it is almost impossible to detect which attack variant has infiltrated their systems,” Newson said.

According to experts, Lazarus’ attacks have recently become more than just a news headline, they have become a source of constant and high-risk threats to the crypto ecosystem. Those operating in the fintech and digital money sectors are recommended to act extra carefully against both technical and social engineering-based attacks in this new period.

Disclaimer: The information contained in this content is not investment advice. Please note that cryptocurrencies involve high volatility and therefore risk. It is recommended that you make your investment decisions based on your own research and risk assessments. You can review our Trust Center page for detailed information.

You Might Also Like

Ethereum Co-Founder Buterin Warns About ‘Smart’ Wallets! User Security May Be At Risk!

He defrauded Cryptocurrency Investors by Selling Subscriptions for $250-500

Bomb Detection from Crypto Detective! 24 Million Dollar MEME Token Linked to a Single Person!

$19 Million Recovered in Attack on US Government Wallet

$6 Million Cryptocurrency Raid by FBI

TAGGED:Security
Share This Article
Facebook Twitter Email Print
Previous Article Striking prediction for 2026 in Bitcoin: The price is rising at critical resistance with a target of $150 thousand
Next Article Why is Bitcoin Price up Today?
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Crypto Live Widget

Follow for Live Updates
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad imageAd image
Popular News
Official Launch Announcement – EdaFace NFT Marketplace
Why Ethereum is Poised to Explode to $4,600 Sooner Than You Think!
Five Altcoins With 100x Potential To Buy Now
ETF Approvals, Regulatory Frameworks, and Market Dynamics
Top News, Bitcoin and Altcoin Volatility, Major Hacks, and DeFi Investments

Company

  • Vision
  • Mission
  • LitePaper
  • Whitepaper
  • Core Values
  • Branding
  • Teams
  • Career Listing
  • FAQ
  • Welfare Donations

Products

  • EDA Coin
  • Blockchain Literature
  • EdaFace Dex
  • EdaFace Mall
  • Listing Platforms
  • Newsfeed
  • NFT Marketplace
  • P2P Market
  • Scam Verification Centre
  • School of Crypto

Legal

  • Term of Use
  • Privacy Policy
  • Disclaimers
  • Contact Us
  • Chat Forun

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

EdaFace

About US

EdaFace is a user interface aggregator that brings all the various functionalities of the crypto industry onto a single platform! You can advertise, launch and crowdfund your crypto project via EdaFace Launchpad and Newsfeed.

Contact us: [email protected]

Follow us

Instagram Twitter Facebook Telegram Youtube Linkedin

Copyright © 2022 – 2026. EdaFace is a product of Emerging Digital Age (EDA) Pty Ltd. All Rights Reserved.

Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..

Zero spam, Unsubscribe at any time.
EdaFace
Welcome Back!

Sign in to your account

Lost your password?