Mach-O Man
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lazarus Group is abusing “ClickFix” social engineering to push a new macOS malware kit dubbed “Mach-O Man,” giving attackers a direct path to credentials, Keychain secrets, and corporate access in fintech and crypto environments.
So, for the lack of a better name, we’re calling this new kit Mach-O Man.
Techniques & procedures
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques
Initial Access
Execution
2 techniques
Execution
Persistence
3 techniques
Persistence
It then creates a LaunchAgent, roughly the macOS equivalent of Windows Services, to maintain persistence by executing OneDrive, which in turn instantiates the previous components on startup.
Privilege Escalation
3 techniques
Privilege Escalation
It then creates a LaunchAgent, roughly the macOS equivalent of Windows Services, to maintain persistence by executing OneDrive, which in turn instantiates the previous components on startup.
Stealth
2 techniques
Stealth
Defense Impairment
1 technique
Defense Impairment
Credential Access
3 techniques
Credential Access
Stage 1 – The Stager ( teamsSDK.bin ) ... prompts the victim for their password three times, with the window shaking on first two attempts to simulate authentication failure before silently accepting credentials.
Discovery
5 techniques
Discovery
a secondary module facilitates system profiling to obtain ... network configuration data
collecting host identifiers, OS details, network configuration, processes, and browser extension data
a second module (variants such as D1YrHRTg.bin) profiles the system via sysctl and local tools, collecting host identifiers, OS details, network configuration, processes, and browser extension data
Collection
3 techniques
Collection
A payload called macrasv2 is downloaded next, acting as stealer targeting browser extension data, stored browser credentials and cookies, macOS Keychain entries, and other files of interest
Command and Control
2 techniques
Command and Control
Exfiltration
2 techniques
Exfiltration
Researchers note that parts of the kit are poorly written, with some profilers entering infinite loops that continuously POST the same data to command-and-control servers... The final stealer stage... aggregates high-value data from the system before exfiltration.
Other
1 technique
Other
The attack begins not with a software exploit, but with a deceptively simple social engineering technique known as ClickFix. Victims ... receive an urgent Telegram message from a compromised or impersonated contact, containing what appears to be a legitimate invitation to a Zoom, Microsoft Teams, or Google Meet session.
IOCs tracked for this family
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS-focused malware kit used in a ClickFix campaign. It delivers an initial staging binary, retrieves fake macOS apps for credential theft, performs system profiling, and ultimately deploys a stealer component to exfiltrate credentials, cookies, Keychain secrets, and other files.
A modular macOS malware kit built in Go as native Mach-O binaries for Intel and Apple Silicon systems. It uses ClickFix-style social engineering and fake meeting apps to deploy a four-stage chain that profiles the host, establishes persistence, steals browser and Keychain data, and exfiltrates collected information via the Telegram Bot API.
A modular macOS malware kit delivered via ClickFix-style social engineering. It uses a stager to fetch fake conferencing or system apps, profiles the host, steals browser credentials and cookies, extracts macOS Keychain data and other files, exfiltrates them in archives, and can establish persistence via LaunchAgents.
A macOS malware kit used by Famous Chollima/Lazarus-linked operators. It is delivered via ClickFix lures on fake meeting sites, deploys Mach-O binaries, steals credentials and browser data, profiles infected hosts, establishes persistence via LaunchAgent, and exfiltrates data including browser credentials, cookies, extension data, and Keychain entries via Telegram and C2 infrastructure.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.