Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat to Crypto and Fintech
Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to turn routine business interactions into a gateway for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained campaign. According to Natalie Newson, a senior blockchain security researcher at CertiK, the crypto industry must view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the recent release of a new macOS malware kit, has raised concerns about the scale and speed of their operations. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which is tailored for Apple environments and uses a delivery method known as ClickFix. This social engineering technique involves tricking victims into pasting a command into their terminal to fix a simulated connection issue, providing immediate access to corporate systems and financial resources. Variations of this attack have already been reported, with some cases involving the hijacking of decentralized finance project domains and the replacement of websites with fake messages. The malware is designed to erase itself after a breach, making it difficult for victims to realize they have been compromised and identify the variant that affected them.