Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a direct conduit for credential theft and data loss. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors. With estimated cumulative loot of $6.7 billion since 2017, the collective has siphoned over $500 million in the past two weeks alone from the Drift and KelpDAO exploits. Newson emphasized that the crypto industry must view Lazarus as a constant and well-funded threat, rather than just a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to deliver the malware. This technique involves sending executives 'urgent' meeting invites, leading them to a fake website that instructs them to paste a command into their terminal to 'fix a connection issue', thereby granting immediate access to corporate systems and financial resources. The attack is particularly dangerous due to its ability to evade traditional security controls, with most victims unaware of the breach until the damage has been done.