Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which transforms ordinary business interactions into a conduit for credential theft and data breaches. The Lazarus Group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech, cryptocurrency, and other industries. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level has increased significantly, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks alone. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to trick victims into providing access to corporate systems and financial resources. The attack involves sending executives urgent meeting invites over Telegram, leading them to a fake website that instructs them to copy and paste a command into their Mac's terminal to 'fix a connection issue.' By doing so, victims unknowingly grant immediate access to their systems, allowing the hackers to operate undetected until it's too late. The malware is designed to erase itself after a breach, making it challenging for victims to identify the variant that affected them.