Lazarus Group's Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business interactions into a means for credential theft and data loss. The Lazarus Group, a state-run collective, is targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has stolen over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained campaign. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the creation of a new macOS malware kit, has raised concerns about the scale and speed of their operations. The Mach-O Man malware kit, created by Lazarus' Chollima division, uses native Mach-O binaries tailored for Apple environments and employs a social engineering technique known as ClickFix. This involves sending executives 'urgent' meeting invites, which lead to a fake website instructing them to paste a command into their terminal to 'fix a connection issue', thereby providing immediate access to corporate systems and financial resources. Variations of this attack have already been identified, with cases of Lazarus attackers hijacking DeFI projects' domains and replacing their websites with fake messages. The malware often erases itself after a breach, making it difficult for victims to identify the variant that affected them.