Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to exploit standard business communication, resulting in credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, they have stolen over $500 million from the Drift and KelpDAO exploits, highlighting the need for the crypto industry to view Lazarus as a constant and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to trick victims into providing access to corporate systems. The attack involves sending 'urgent' meeting invites over Telegram, leading to a fake website that instructs victims to paste a command into their terminal to 'fix a connection issue', thereby granting immediate access to sensitive resources. Variations of this attack have already been identified, with some cases involving the hijacking of DeFI projects' domains and the use of fake Cloudflare messages to trick victims into entering harmful commands. The malware often erases itself after a successful attack, making it challenging for victims to realize they have been breached and identify the specific variant used.