Back to Feed
Nation-stateApr 24, 2026

North Korea's Lazarus Targets macOS Users via ClickFix

Lazarus Group targets macOS users via ClickFix for initial access and data theft.

Vendor Watch

Run macOS?

Get an email when a reviewed story names macOS, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

North Korea's Lazarus Group is actively exploiting ClickFix, a fake tech support scam, to compromise macOS systems and steal data from high-value targets within Mac-centric organizations. The campaign demonstrates the group's expansion of initial-access tactics beyond Windows platforms to target Apple users. This represents a continued evolution of Lazarus's social engineering and credential harvesting capabilities.

Indicators of Compromise

  • malware — ClickFix

Entities

Lazarus Group (threat_actor)macOS (product)