Lazarus Group Intensifies Threat with Mach-O Man Attack, Warns CertiK

Security experts have alerted to a new campaign, known as 'Mach-O Man', launched by the North Korean state-sponsored Lazarus Group, which transforms ordinary business interactions into a direct route for credential theft and data compromise. The group, estimated to have amassed $6.7 billion since 2017, is primarily targeting high-value executives and firms within the fintech and cryptocurrency sectors, according to Natalie Newson, a senior blockchain security researcher at CertiK. Over the past two weeks, the North Korean hackers have successfully siphoned over $500 million from exploits such as Drift and KelpDAO, underscoring the sustained nature of their campaign. Newson emphasized that the crypto industry must acknowledge Lazarus as a perpetual and well-funded threat, rather than merely another news headline. The group's heightened activity level, marked by the deployment of a new macOS malware kit, underscores the state-directed financial operation's scale and speed, characteristic of institutional operations. North Korea has effectively established crypto theft as a lucrative national industry, with Mach-O Man being the latest product of this process. Although created by Lazarus, other cybercrime groups are also leveraging this malware. Mach-O Man is a modular macOS malware kit developed by Lazarus Group's Chollima division, utilizing native Mach-O binaries tailored for Apple environments prevalent in the crypto and fintech sectors. The malware employs a delivery method known as ClickFix, a social engineering technique where victims are instructed to paste a command into their terminal to resolve a simulated connection issue. This technique involves sending executives 'urgent' meeting invites over Telegram for video conferencing platforms, redirecting them to a convincing yet fake website that instructs them to copy and paste a command into their Mac's terminal to 'fix a connection issue', thereby granting immediate access to corporate systems, SaaS platforms, and financial resources. By the time the exploit is discovered, the damage is often irreparable. Variations of this attack have been identified, with instances of Lazarus attackers hijacking DeFI project domains using the malware, replacing their websites with fake Cloudflare messages that prompt victims to enter commands, effectively running harmful commands. These 'verification steps' guide victims through keyboard shortcuts, often evading traditional security controls. Most victims remain unaware of the security breach until the damage is done, at which point the malware has typically self-erased, leaving victims uncertain about the variant that affected them.