Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to turn ordinary business interactions into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the hackers have successfully siphoned over $500 million from the Drift and KelpDAO exploits, underscoring the need for the crypto industry to view Lazarus as a persistent and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' infamous Chollima division, which employs a social engineering technique known as ClickFix to trick victims into granting access to corporate systems. The attack involves sending fake meeting invites over Telegram, leading to a convincing but malicious website that instructs victims to paste a command into their terminal, thereby providing immediate access to sensitive resources. With several variations of this attack already identified, security experts caution that most victims will not realize they have been breached until the damage has been done, and the malware has self-erased.