Lazarus Group Malware Targets Crypto, Business Execs via macOS | News World

Browse the world's leading international and domestic Airlines. Compare rates and availabilty for any destination and route.

Security researchers have linked a new macOS malware campaign to the Lazarus Group, the North Korea-linked hacking operation behind some of the crypto industry’s biggest thefts.

Flagged on Tuesday, the new “Mach-O Man” malware kit is distributed via “ClickFix” social engineering schemes across traditional businesses and crypto companies, according to Mauro Eldritch, offensive security expert and founder of threat intelligence company BCA Ltd.

Victims are lured into a fake Zoom or Google Meet call where they are prompted to execute commands that download the malware in the background, allowing attackers to bypass traditional controls without detection to gain access to credentials and corporate systems, the security researcher said in a Tuesday report.

Researchers said the…

more
Source cointelegraph.com

FTC: We use income earning affiliate links. More on Sposored links.
Terms of use and third-party services. More here.

lyrics2.me  | Billboard |  Rolling Stone |  K-Pop

Related Posts

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension | Cybersecurity

Ravie LakshmananMay 21, 2026Supply Chain Attack / Developer Tools GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee…

Read more

Firefox 151 packs big privacy upgrades into a small update | Malware

Mozilla has published release notes for Firefox browser version 151.0, and this update includes several genuinely meaningful privacy and security improvements. Three changes stand out in particular: Stronger anti‑fingerprinting Broader…

Read more

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development | Cybersecurity

Ravie LakshmananMay 20, 2026Artificial Intelligence / Security Testing Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence…

Read more

Fake malware-signing service Fox Tempest dismantled by Microsoft | Malware

Microsoft says it dismantled a malware-signing-as-a-service (MSaaS) called Fox Tempest, which helped cybercriminals make malware appear legitimate. The service let customers submit malicious files to be digitally signed with short-lived…

Read more

Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API | Cybersecurity

Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or…

Read more

Grafana GitHub Breach Exposes Source Code via TanStack npm Attack | Cybersecurity

Ravie LakshmananMay 20, 2026Supply Chain Attack / Cloud Security Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or…

Read more

Facebook scam promises cheap Aldi meat boxes, steals payment info instead | Malware

Sometimes you spot posts on social media that make you wonder if any moderation takes place at all. Which is concerning, because two–thirds of all online shopping scams now start…

Read more

Biometrics, diagnoses, and bank details exposed in major healthcare breach | Malware

NYC Health + Hospitals (NYC H+H) posted a data breach notice about a months‑long breach via a third‑party vendor that exposed highly sensitive patient and employee data for at least…

Read more

Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps | Cybersecurity

Ravie LakshmananMay 19, 2026Malvertising / Mobile Security Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, per HUMAN’s…

Read more

The New Phishing Click: How OAuth Consent Bypasses MFA | Cybersecurity

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.  The targets of the…

Read more

YouTube wants your face to fight deepfakes | Malware

If you’re worried about deepfake likenesses of yourself showing up online, you’re not alone; YouTube is worried for you. It wants to protect you by having you upload a selfie…

Read more

Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials | Cybersecurity

Ravie LakshmananMay 19, 2026Software Security / Malware In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests…

Read more

AI is distorting the Holocaust (Lock and Code S07E10) | Malware

This week on the Lock and Code podcast… In May of last year, a warning about AI came from somewhere unexpected: The Auschwitz-Birkenau State Museum. Posting publicly on social media,…

Read more

INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests | Cybersecurity

INTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the identification of an additional 382 suspects. The initiative…

Read more

⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More | Cybersecurity

Ravie LakshmananMay 18, 2026Cybersecurity / Hacking Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned….

Read more

Microsoft is changing Edge’s plaintext password behavior | Malware

Microsoft said it will change Edge’s password handling as a “defense‑in‑depth” measure. Originally, Edge decrypted the entire saved‑password store on startup and kept all credentials resident in process memory in…

Read more

Developer Workstations Are Now Part of the Software Supply Chain | Cybersecurity

Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns…

Read more

A week in security (May 11 – May 17) | Malware

Last week on Malwarebytes Labs: Attackers replaced JDownloader installer downloads with malware Meta’s confusing new approach to chat privacy Why Malwarebytes blocks some Yahoo Mail redirects Fake Claude search results…

Read more

MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems | Cybersecurity

Ravie LakshmananMay 18, 2026Zero Day / Vulnerability Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege…

Read more

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt | Cybersecurity

Ravie LakshmananMay 17, 2026Data Breach / Cybercrime Grafana has disclosed that an “unauthorized party” obtained a token that granted them the ability to access the company’s GitHub environment and download…

Read more

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming | Cybersecurity

Ravie LakshmananMay 16, 2026Vulnerability / Website Security A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript…

Read more

Meta’s confusing new approach to chat privacy | Malware

Recent news had us wondering whether Meta actually knows what it wants. On one platform, Meta is promoting AI chats that it says even it cannot read. On another, it…

Read more

Attackers replaced JDownloader installer downloads with malware | Malware

If you downloaded the JDownloader installer during the compromise window (May 6-7), you are advised to verify the file.  JDownloader is a popular download management application, particularly favored for automated…

Read more

Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access | Cybersecurity

Ravie LakshmananMay 15, 2026Botnet / Threat Intelligence The Russian state-sponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that’s engineered for…

Read more

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface | Cybersecurity

The Hacker NewsMay 15, 2026Endpoint Security / Threat Detection In Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust, we made a simple argument: the most dangerous…

Read more

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email | Cybersecurity

Ravie LakshmananMay 15, 2026Microsoft / Vulnerability Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild….

Read more

USB stick opens Windows BitLocker drives in new zero-day | News World

An unnamed security researcher using the monikers “Nightmare-Eclipse” and “Chaotic Eclipse” has published a simple bypass for Microsoft’s disk encryption technology BitLocker on Windows, using a memory stick with specially…

Read more

Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access | Cybersecurity

Ravie LakshmananMay 14, 2026Vulnerability / Network Security Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited…

Read more

Deepfake sextortion forces schools to remove student photos from websites | Malware

Schools love a good photo, whether it’s from a trip to a castle, a science prize ceremony, or sports day shot from three angles. For two decades, celebratory images like…

Read more

ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories | Cybersecurity

Ravie LakshmananMay 14, 2026Hacking News / Cybersecurity News Everything is still on fire. This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady…

Read more
Update cookies preferences