• About
  • FAQ
  • Landing Page
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
Crypto News
No Result
View All Result
Home Market

North Korea’s Lazarus Group Is Targeting Crypto Executives With Fake Meeting Invites

admin by admin
April 23, 2026
in Market
0
North Korea’s Lazarus Group Is Targeting Crypto Executives With Fake Meeting Invites
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

North Korea’s Lazarus Group Is Targeting Crypto Executives With Fake Meeting Invites插图

North Korea’s Lazarus Group has launched a new macOS malware campaign called Mach-O Man that uses fake online meeting invitations to trick crypto and fintech executives into executing malicious commands on their own devices, according to blockchain security firm CertiK.

Summary

  • Lazarus Group’s new Mach-O Man campaign uses fake meeting invites to lure executives into pasting malicious terminal commands on their Macs.
  • The malware auto-deletes after execution, making the breach nearly impossible to detect through standard forensic methods.
  • CertiK links the same Lazarus push to over $500 million stolen from DeFi platforms Drift and KelpDAO in the past two weeks.

North Korea’s Lazarus Group is running a new campaign dubbed Mach-O Man that targets executives at crypto, fintech, and other high-value firms by disguising malware delivery as a routine technical fix during a fake business meeting, according to CertiK senior blockchain security researcher Natalie Newson. The campaign was disclosed on April 22 and represents one of the group’s most operationally sophisticated social engineering methods to date.

Lazarus Group Crypto Hack Hides Behind Routine Business Communications

The attack chain begins with an urgent-looking meeting invitation sent over Telegram, impersonating a Zoom, Microsoft Teams, or Google Meet call. The link leads to a convincing but fake website that tells the victim to paste a single command into their Mac terminal to resolve an apparent connection issue, a technique CertiK identifies as ClickFix. Once executed, the command installs a modular malware kit built from native Mach-O binaries tailored for Apple environments, which profiles the host, establishes persistence, and exfiltrates credentials and browser data through a Telegram-based command-and-control channel. Critically, the toolkit auto-deletes after completing its task, making detection and forensic analysis extremely difficult. “These fake verification steps guide victims through keyboard shortcuts that run a harmful command,” CertiK’s Newson told CoinDesk. “The page looks real, the instructions seem normal, and the victim initiates the action themselves, which is why traditional security controls often miss it.”

Why This Attack Is Harder to Catch Than Standard Phishing

Unlike traditional phishing attacks that rely on urgency cues or suspicious sender addresses, the Mach-O Man campaign is designed to look entirely routine at the moment of delivery. Executives in crypto and fintech routinely receive cold outreach from investors, researchers, and business partners, making the fake meeting invitation format a credible lure in a way that generalized phishing often is not. CertiK’s analysis notes that the Mach-O Man framework is tied to Lazarus’ Famous Chollima unit and distributed through compromised Telegram accounts specifically targeting high-value organizations in the digital asset space. Most victims will not realize they have been compromised until well after the malware has erased itself. “They likely don’t know it yet,” Newson said. “If they do, they probably can’t identify which variant affected them.”

The Scale of the Lazarus Threat to Crypto in 2026

CertiK has linked the Mach-O Man campaign to a broader Lazarus offensive that has siphoned more than $500 million from DeFi platforms Drift and KelpDAO in under two weeks, adding to a cumulative theft total estimated at $6.7 billion since 2017. The United Nations has previously estimated that North Korean hackers have stolen several billion dollars in digital assets to fund the country’s weapons programs. “What makes Lazarus especially dangerous right now is their activity level,” Newson said. “This isn’t random hacking. It’s a state-directed financial operation running at a scale and speed typical of institutions.” CertiK is advising crypto professionals to independently verify all meeting requests through a separate channel before clicking any link or downloading any attachment from an unsolicited invitation.

CertiK has shared indicators of compromise tied to the Mach-O Man campaign with the broader security community to support detection and defense efforts across the industry.

News,Cryptocurrency,Lazarus Group,North Korea#North #Koreas #Lazarus #Group #Targeting #Crypto #Executives #Fake #Meeting #Invites1776916059

Related articles

How event contracts get listed: Self-certification

How event contracts get listed: Self-certification

July 27, 2026
Japan crypto leverage: Why is Japan considering higher crypto leverage limits? - 1

Japan crypto leverage: Why is Japan considering higher crypto leverage limits?

July 27, 2026
Tags: CryptoExecutivesfakeGroupInvitesKoreasLazarusMeetingNorthTargeting
Share76Tweet47

Related Posts

How event contracts get listed: Self-certification

How event contracts get listed: Self-certification

by admin
July 27, 2026
0

A US exchange can list a new prediction market by filing a form saying the contract complies with the law,...

Japan crypto leverage: Why is Japan considering higher crypto leverage limits? - 1

Japan crypto leverage: Why is Japan considering higher crypto leverage limits?

by admin
July 27, 2026
0

Japan has moved closer to easing its cryptocurrency leverage trading rules after a senior ruling party lawmaker said the current...

Garden Finance takes app offline after independent solver database compromise - 1

Garden Finance takes app offline after independent solver database compromise

by admin
July 27, 2026
0

Garden Finance has temporarily taken its application offline after an attacker compromised the off-chain database of an independent solver, leading...

Brian Armstrong’s NewLimit Raises $435M for Human Trials

Brian Armstrong says AI agents will out-transact humans using crypto

by admin
July 27, 2026
0

Coinbase chief executive Brian Armstrong said artificial intelligence and crypto are not rival trends. Summary Armstrong expects autonomous AI agents...

Sberbank sets Dec. 1 deadline for Russia crypto trading launch

Sberbank sets Dec. 1 deadline for Russia crypto trading launch

by admin
July 26, 2026
0

Sberbank plans to launch cryptocurrency trading infrastructure and a digital depository by Dec. 1, 2026. Summary Sberbank plans to launch...

Load More
  • Trending
  • Comments
  • Latest
Rain raises $250m series C to expand stablecoin payments infrastructure - 1

Rain raises $250m series C to expand stablecoin payments infrastructure

January 10, 2026
US Commodities Regulator Beefs Up Bitcoin Futures Review缩略图

US Commodities Regulator Beefs Up Bitcoin Futures Review

January 16, 2023
What is the Difference Between Public and Permissioned Blockchains?缩略图

What is the Difference Between Public and Permissioned Blockchains?

December 28, 2022
Elon Musk Offers to Buy 100% of Twitter, Calls it ‘Best and Final Offer’

Elon Musk Offers to Buy 100% of Twitter, Calls it ‘Best and Final Offer’

March 4, 2023
US Commodities Regulator Beefs Up Bitcoin Futures Review缩略图

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability缩略图

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech缩略图

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55缩略图

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
sberbank

Sberbank to Launch Crypto Trading and Custody Platform by December

July 27, 2026
Solar-Powered Bitcoin Mine Brews Up Big Savings for NSW Brewery

Solar-Powered Bitcoin Mine Brews Up Big Savings for NSW Brewery

July 27, 2026
How event contracts get listed: Self-certification

How event contracts get listed: Self-certification

July 27, 2026
Triple-A Crypto Wallet Hack Swells to Nearly $12 Million

Triple-A Crypto Wallet Hack Swells to Nearly $12 Million

July 27, 2026
Crypto News

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

Categories tes

  • Bitcoin
  • Blockchain
  • Business
  • Ethereum
  • Guide
  • Market
  • Regulation
  • Ripple

Tags

Act Bitcoin BTC CLARITY Coinbase Crypto data DeFi ETF ETFs ETH Ethereum Eyes Faces hit hits Hyperliquid Iran key launch launches Market markets million Network Onchain prediction price Push rally Ripple risk Solana Stablecoin stock Strategy support targets Token tokenized trading Trump U.S Warns XRP

Newsletter

[mc4wp_form]

  • About
  • FAQ
  • Support Forum
  • Landing Page
  • Contact Us

© 2017 JNews - Crafted with love by Jegtheme.

No Result
View All Result
  • Contact Us
  • Homepages
  • Business
  • Guide

© 2018 JNews by Jegtheme.