Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which enables the Lazarus Group to transform ordinary business communication into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective's activity level has increased significantly, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks. Newson emphasized that the crypto industry must recognize the Lazarus Group as a constant and well-funded threat, rather than just a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by the group's Chollima division, which employs a social engineering technique known as ClickFix to deliver the malware. This technique involves sending executives 'urgent' meeting invites over Telegram, leading them to a fake website that instructs them to copy and paste a command into their Mac's terminal to 'fix a connection issue.' By doing so, victims unwittingly provide immediate access to corporate systems, SaaS platforms, and financial resources. The attack has several variations, and security researchers have already identified cases where Lazarus attackers have hijacked DeFI projects' domains using this new malware. The fake 'verification steps' guide victims through keyboard shortcuts that run a harmful command, often evading traditional security controls. Most victims will not realize their security has been breached until the damage has been done, at which point the malware will have already erased itself.