Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data compromise. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is primarily targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective's recent activities, including the Drift and KelpDAO exploits, which have resulted in losses exceeding $500 million, demonstrate a sustained and well-funded campaign. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which leverages native Mach-O binaries tailored for Apple environments. This malware kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. The attack begins with an 'urgent' meeting invitation sent to executives over Telegram, directing them to a fake website that instructs them to copy and paste a command into their Mac's terminal. By doing so, victims inadvertently grant immediate access to corporate systems, SaaS platforms, and financial resources. The malware is designed to erase itself after a successful breach, making it challenging for victims to detect and identify the specific variant used in the attack.