Lazarus Group's Mach-O Man Attack Poses Significant Threat to Crypto and Fintech Firms
Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to turn routine business communications into a direct path for credential theft and data loss. The group, responsible for an estimated $6.7 billion in loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained campaign. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the creation of a new macOS malware kit, has raised concerns among security experts. The Mach-O Man campaign uses a modular macOS malware kit, created by Lazarus Group's Chollima division, which utilizes native Mach-O binaries tailored for Apple environments. The kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to 'fix a connection issue'. This technique has already been used to hijack DeFI projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The attack often goes undetected until the damage has been done, at which point the malware has already erased itself.