Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK
Security experts warn that the North Korean state-run Lazarus Group has launched a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a direct route for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors, according to Natalie Newson, a senior blockchain security researcher at CertiK. In recent weeks, the group has stolen over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained campaign. Newson emphasizes that the crypto industry must view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the KelpDAO, Drift, and a new macOS malware kit, all within the same month, indicates a state-directed financial operation. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which uses native Mach-O binaries tailored for Apple environments. The delivery method, known as ClickFix, involves a social engineering technique where victims are asked to paste a command into their terminal to fix a simulated connection issue. This technique allows Lazarus to send executives 'urgent' meeting invites, leading to a fake website that instructs them to copy and paste a command, providing immediate access to corporate systems, SaaS platforms, and financial resources. By the time victims realize they have been exploited, it is often too late. Variations of this attack have already been reported, with cases of Lazarus attackers hijacking DeFI projects' domains and replacing their websites with fake messages. The fake 'verification steps' guide victims through keyboard shortcuts that run a harmful command, often evading traditional security controls. Most victims will not realize their security has been breached until the damage has been done, and the malware will have already erased itself.