According to CertiK, the Lazarus Group is conducting an attack campaign called Mach-O Man targeting executives in the fintech and cryptocurrency industries. This operation utilizes ClickFix social engineering techniques to send fake online meeting invitations, tricking victims into pasting repair instructions into their Macs, thereby gaining access to company and financial systems. CertiK researcher Natalie Newson stated that the Lazarus Group has stolen over $500 million in the past two weeks through attacks on Drift and KelpDAO. Mach-O Man is a modular macOS malware toolkit developed by the Chollima division of the Lazarus Group, capable of automatically deleting itself after use to evade detection. Furthermore, attackers have already carried out this attack by hijacking DeFi project domains and replacing them with fake Cloudflare messages.