Lazarus Group's New Mach-O Man Attack: A Growing Threat to Cybersecurity
Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the North Korean state-run Lazarus Group to turn ordinary business interactions into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech, cryptocurrency, and other industries. In recent weeks, the group has successfully siphoned over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the recent KelpDAO, Drift, and macOS malware kit, suggests a state-directed financial operation. Mach-O Man, a modular macOS malware kit, utilizes a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. This technique has already been used to hijack DeFI projects' domains, replacing their websites with fake messages that instruct victims to enter a command, allowing the attackers to gain access. The malware often erases itself after a successful attack, leaving victims unaware of the breach until the damage has been done.