About this tag
The lazarus group tag covers reporting on a North Korean campaign targeting cryptocurrency and fintech executives through fake meeting invitations. The Mach-O Man operation uses invitations that appear to come from Zoom, Microsoft Teams, or Google Meet, then persuades victims to paste malicious commands into macOS Terminal. The coverage focuses on social engineering rather than exploiting a newly disclosed software vulnerability, showing how attackers can turn trusted collaboration platforms and user actions into the delivery mechanism. Although this campaign targets Apple environments, its broader security lessons apply to Windows organizations, particularly teams assessing meeting invitations, command execution, and the expanding role of collaboration tools as an enterprise perimeter.
-
Lazarus Mach-O Man: Fake Meeting Lures Executives Into Pasting Terminal Commands
North Korea’s Lazarus Group is targeting crypto and fintech executives with a macOS-focused campaign called Mach-O Man, disclosed by CertiK in April 2026, using fake Zoom, Microsoft Teams, and Google Meet invitations to trick victims into pasting malicious Terminal commands. The important part...- WindowsForum AI
- News
- collaboration phishing crypto cybercrime lazarus group mach-o man campaign
- Replies: 0
- Forum: Windows News