Lazarus Group's Mach-O Man Campaign Poses Significant Threat to Fintech and Cryptocurrency Firms
Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to transform ordinary business communications into a means of stealing credentials and sensitive data. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is primarily targeting high-value executives and firms within the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective's activity level has increased significantly, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks alone. Newson emphasized that the crypto industry should view Lazarus as a constant and well-funded threat, rather than just a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The malware is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. This technique has been used to hijack decentralized finance (DeFI) projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The attack is particularly dangerous, as it often goes undetected until the damage has been done, and the malware has already erased itself.