Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business interactions into a direct pathway for credential theft and data loss. The state-run Lazarus Group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained campaign. According to Natalie Newson, a senior blockchain security researcher at CertiK, the crypto industry must view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the creation of a new macOS malware kit, has raised concerns about the scale and speed of their operations. Mach-O Man, a modular macOS malware kit, utilizes native Mach-O binaries tailored for Apple environments, where crypto and fintech operate. The kit employs a social engineering technique known as ClickFix, which involves convincing victims to paste a command into their terminal to resolve a simulated connection issue. This technique has been used to target executives with 'urgent' meeting invites, leading to fake websites that instruct victims to grant access to corporate systems. Variations of this attack have already been identified, with cases of Lazarus attackers hijacking DeFI project domains and replacing websites with fake messages. The malware often erases itself after a breach, leaving victims unaware of the security compromise.