By using this site, you agree to the Privacy Policy..
Accept
Latest cryptocurrency newsLatest cryptocurrency newsLatest cryptocurrency news
  • BITCOIN
  • Crypto Tracker App
  • ETHEREUM
  • RIPPLE
  • Crypto News
  • FINANCE NEWS
  • BLOCKCHAIN
  • CONTACT
  • TURKISHTURKISHTURKISH
Reading: Elusive Cybercrime Syndicate Targets Digital Finance
Share
Font ResizerAa
Latest cryptocurrency newsLatest cryptocurrency news
Font ResizerAa
  • BITCOIN
  • Crypto Tracker App
  • ETHEREUM
  • RIPPLE
  • Crypto News
  • FINANCE NEWS
  • BLOCKCHAIN
  • CONTACT
  • TURKISHTURKISHTURKISH
Follow US
© 2025 BLOCKCHAIN Information Technologies. >> BH NEWS.
Powered By LK SOFTWARE
Latest cryptocurrency news > CRYPTOCURRENCY SECURITY > Elusive Cybercrime Syndicate Targets Digital Finance
CRYPTOCURRENCY SECURITY

Elusive Cybercrime Syndicate Targets Digital Finance

BH NEWS
Last updated: 22 April 2026 16:36
BH NEWS 2 hours ago
Share
SHARE

Contents
Who Are the New Targets?What Makes ClickFix So Effective?Is DeFi Becoming a Hotspot?

Lazarus Group, a notorious cybercriminal entity with alleged ties to North Korea, is pivoting its focus towards exploiting the rapidly evolving cryptocurrency and fintech sectors. Since its inception in 2017, the group has been implicated in cyber heists totaling a staggering $6.7 billion. Their latest initiative, “Mach-O Man,” zeroes in on executives and businesses within digital finance, capitalizing on emerging vulnerabilities to obtain extensive digital assets.

Who Are the New Targets?

Natalie Newson, a blockchain security authority at CertiK, has been closely following Lazarus Group’s intensified operations targeting the crypto and fintech realms. Within the past fortnight, Lazarus executed digital asset thefts amounting to over $500 million from entities such as Drift and KelpDAO. Investigators assert that the Mach-O Man initiative is far from a random occurrence but rather a concerted effort bolstered and directed at the state level by North Korea.

What Makes ClickFix So Effective?

The hallmark of the Mach-O Man assault is its sophisticated macOS malware, forged by Lazarus’s “Chollima” subgroup, specifically designed to infiltrate crypto and fintech applications on Apple systems. Newson notes the malware is disseminated through a tailored social engineering scheme branded as “ClickFix.”

Hackers approach executives via Telegram, issuing urgent meeting requests. The unsuspecting victims are rerouted to seemingly legitimate sites mimicking major platforms like Zoom or Microsoft Teams, where they are instructed that minor connection troubles necessitate pasting a specific command into their terminal, thereby granting cybercriminals unrestricted access to corporate systems and sensitive assets.

“The page appears entirely legitimate, and the instructions seem routine—the victim initiates the action themselves, so conventional security checks rarely detect the attack,” Newson explains.

Is DeFi Becoming a Hotspot?

The advanced tactics of Mach-O Man have resonated across the sector, severely threatening organizations and individuals, especially within Decentralized Finance (DeFi). Cybersecurity expert Vladimir S. reports intrusions where attackers hijacked DeFi project domains, substituting them with fraudulent Cloudflare prompts that command users to perform malicious actions for purported “authentication.”

Such deceptive prompts are so persuasively crafted that a majority of users, including high-level personnel, comply without question, inadvertently facilitating total compromise of the platform. The malware is designed to self-erase swiftly, leaving minimal traces and complicating forensic investigations.

“Most victims never realize they’ve been breached. Even if they do, it’s almost impossible to identify which variant infiltrated their systems,” Newson observes.

Specialists indicate that the threat emanating from Lazarus Group is evolving from isolated incidents to a continuous and dangerous menace impacting the broader crypto ecosystem. Stakeholders in fintech and digital currencies are strongly advised to heighten both technological and procedural defenses to thwart looming threats.

You can follow our news on Telegram and Coinmarketcap
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

Cybersecurity Alert at Velvet Capital Following Phishing Scam

SlowMist Alerts Users About New Scam

ByBit Wallet Hack Triggers Major Market Reaction

Cloud Infrastructure Giant Faces Security Breach: Crypto Apps in Limbo

Platypus Hackers Who Stole $8.5 Million Released Without Charges

Share This Article
Facebook X Email Print
Previous Article Bitcoin’s Future: Will 2026 See a Meteoric Rise?
Next Article US Ceasefire Extension Sparks BTC Rally and Market Turbulence
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Middle East Tensions Keep Investors on Edge as Cryptocurrency Markets React
BITCOIN (BTC)
Power Moves: Iren’s Energy Edge in the Data Center Domain
BITCOIN (BTC)
Crypto Boom: BTC and ETH Climb as Markets Rebound
BITCOIN (BTC)
Tax Filing Complexity Grows as Crypto Exchange Sends Millions of Forms
Cryptocurrency Law
US Ceasefire Extension Sparks BTC Rally and Market Turbulence
Cryptocurrency
Bitcoin’s Future: Will 2026 See a Meteoric Rise?
BITCOIN (BTC)

CRYPTOCURRENCIES

  • Avalanche (AVAX)
  • Cardano (ADA)
  • CHAINLINK (LINK)
  • Solana (SOL)
about us

Stay informed with BH NEWS, your trusted source for the latest cryptocurrency news, trends, and analysis. From market updates to blockchain innovations, we deliver the insights you need to navigate the world of digital assets confidently.

OUR PARTNERS

  • COINTURK NEWS
  • NEWSLINKER
  • 21MILYON
  • COINTURK

Corporate

  • About Us
  • Cookie Policy
  • Contact

Find Us on Socials

© 2026 BH NEWS.
Powered By LK SOFTWARE
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?