Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to turn ordinary business communications into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has stolen over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained and well-funded campaign. The Mach-O Man malware kit, created by Lazarus' Chollima division, is a modular macOS malware that uses native Mach-O binaries tailored for Apple environments. It employs a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to 'fix' a simulated connection issue, thereby granting immediate access to corporate systems and financial resources. The attack is virtually undetectable, with most victims remaining unaware of the breach until the damage has been done, and the malware has self-erased.