Lazarus Group Intensifies Threat with Mach-O Man Attack, Warns CertiK
Security experts have sounded the alarm over a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a conduit for credential theft and data compromise. The Lazarus Group, a state-sponsored collective with estimated cumulative loot of $6.7 billion since 2017, is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group has stolen over $500 million in the past two weeks alone, highlighting the need for the crypto industry to regard Lazarus as a persistent and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to trick victims into granting access to corporate systems and financial resources. The attack involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal to 'fix a connection issue', thereby providing immediate access to sensitive information. With several variations of this attack already identified, security researchers warn that most victims will remain unaware of the breach until the damage has been done, at which point the malware will have self-erased, making it challenging to identify the specific variant used.