{"id":1007,"date":"2026-04-30T15:12:03","date_gmt":"2026-04-30T13:12:03","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=1007"},"modified":"2026-05-01T15:12:38","modified_gmt":"2026-05-01T13:12:38","slug":"new-lazarus-apt-campaign-mach-o-man-macos-malware-kit-hits-businesses","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2026\/04\/30\/new-lazarus-apt-campaign-mach-o-man-macos-malware-kit-hits-businesses\/","title":{"rendered":"New Lazarus APT Campaign: \u201cMach-O Man\u201d macOS Malware Kit Hits Businesses"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\" id=\"ember59\">The recent wave of ClickFix attacks has introduced several new ways to compromise users, establishing itself as a technique that is likely here to stay. We have observed Lazarus Group using this method to distribute a range of malware, from well-known families to more unusual variants such as PyLangGhostRAT, a Python-based vibe-ported of the original Go version, along with other oddities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ember60\">In this article, we analyze the next stage of this campaign: a newly identified macOS malware kit that is currently being actively distributed.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2026\/04\/30\/new-lazarus-apt-campaign-mach-o-man-macos-malware-kit-hits-businesses\/\" target=\"_self\"><a href=\"https:\/\/www.linkedin.com\/pulse\/new-lazarus-apt-campaign-mach-o-man-macos-malware-up5ce\/\">(4) New Lazarus APT Campaign: \u201cMach-O Man\u201d macOS Malware Kit Hits Businesses | LinkedIn<\/a><span class=\"screen-reader-text\">: New Lazarus APT Campaign: \u201cMach-O Man\u201d macOS Malware Kit Hits Businesses<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>The recent wave of ClickFix attacks has introduced several new ways to compromise users, establishing itself as a technique that is likely here to stay. We have observed Lazarus Group using this method to distribute a range of malware, from well-known families to more unusual variants such as PyLangGhostRAT, a&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[72,39],"class_list":["post-1007","post","type-post","status-publish","format-standard","hentry","category-malware","tag-72","tag-north-korea"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=1007"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1007\/revisions"}],"predecessor-version":[{"id":1008,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1007\/revisions\/1008"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=1007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=1007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=1007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}