Lazarus Group's Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency
Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to turn routine business communication into a direct path to credential theft and data loss. The group, with estimated cumulative loot of $6.7 billion since 2017, is targeting high-value executives and firms, including those in the fintech and cryptocurrency industries. In recent weeks, the group has siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained campaign. The crypto industry is being urged to view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the creation of a new macOS malware kit, has raised concerns among security experts. The Mach-O Man campaign uses a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to 'fix a connection issue', providing immediate access to corporate systems, SaaS platforms, and financial resources. The attack is often only detected after the damage has been done, and the malware has erased itself.