<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🚨#Lazarus Mach-O Man toolkit targets corporate systems and credentials, causing downtime and financial losses.]]></title><description><![CDATA[<p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f6a8.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--rotating_light" style="height:23px;width:auto;vertical-align:middle" title="🚨" alt="🚨" />#Lazarus Mach-O Man toolkit targets corporate systems and credentials, causing downtime and financial losses. A meeting invite in Telegram launches a multi-stage infection chain. </p><p>To evade detection, the malware disguises itself as legitimate system processes, deploying Mach-O binaries. The final stealer harvests browser extensions, saved credentials, and Keychain entries — exfiltrating everything via the Telegram Bot API.</p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2757.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--exclamation" style="height:23px;width:auto;vertical-align:middle" title="❗" alt="❗" />️ Explore macrasv2 execution chain in a sandbox session and update your detection rules: <a href="https://app.any.run/tasks/94b9bc1f-86ff-4069-8222-1cb511d78ad9/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=lazarus_macos_case&amp;utm_term=290426&amp;utm_content=linktoservice" rel="nofollow noopener"><span>https://</span><span>app.any.run/tasks/94b9bc1f-86f</span><span>f-4069-8222-1cb511d78ad9/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=lazarus_macos_case&amp;utm_term=290426&amp;utm_content=linktoservice</span></a></p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f468-200d-1f4bb.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--male-technologist" style="height:23px;width:auto;vertical-align:middle" title="👨‍💻" alt="👨‍💻" /> Stay one step ahead with defense tips: <a href="https://any.run/cybersecurity-blog/lazarus-macos-malware-mach-o-man/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=lazarus_macos_case&amp;utm_term=290426&amp;utm_content=linktoblog" rel="nofollow noopener"><span>https://</span><span>any.run/cybersecurity-blog/laz</span><span>arus-macos-malware-mach-o-man/?utm_source=mastodon&amp;utm_medium=post&amp;utm_campaign=lazarus_macos_case&amp;utm_term=290426&amp;utm_content=linktoblog</span></a></p><p><a href="https://infosec.exchange/tags/cybersecurity" rel="tag">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" rel="tag">#<span>infosec</span></a></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/487/420/076/524/681/original/4936cea32a93bce2.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/a90c048e-1952-4436-bcb4-5ccb42df8dd8/lazarus-mach-o-man-toolkit-targets-corporate-systems-and-credentials-causing-downtime-and-financial-losses.</link><generator>RSS for Node</generator><lastBuildDate>Tue, 26 May 2026 06:34:19 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/a90c048e-1952-4436-bcb4-5ccb42df8dd8.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Apr 2026 10:03:02 GMT</pubDate><ttl>60</ttl></channel></rss>