Lazarus Group's Mach-O Man Attack Elevates Threat Level: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which transforms standard business interactions into a direct conduit for credential theft and data compromise. The Lazarus Group, a state-sponsored collective, is targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has been linked to the theft of over $500 million from the Drift and KelpDAO exploits, highlighting the need for the crypto industry to regard Lazarus as a persistent and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to deceive victims into granting access to corporate systems. The attack involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal, thereby providing immediate access to sensitive resources. Variations of this attack have already been identified, with some cases involving the hijacking of DeFi project domains and the use of fake Cloudflare messages to trick victims into executing harmful commands.