Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to exploit ordinary business interactions, resulting in credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective has siphoned over $500 million in the past two weeks alone, highlighting the need for the crypto industry to view Lazarus as a constant and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to deliver the malware. This technique involves sending executives 'urgent' meeting invites, leading to a fake website that instructs them to copy and paste a command into their terminal, thereby granting immediate access to corporate systems and financial resources. The attack is often undetectable until the damage has been done, and the malware has erased itself. Variations of this attack have already been identified, with cases of Lazarus attackers hijacking DeFI projects' domains and replacing their websites with fake messages from Cloudflare.