Lazarus Group's New Mach-O Man Attack Heightens Threat Level: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data breaches. The group, known for its state-sponsored cyber operations, has been linked to cumulative losses of $6.7 billion since 2017, targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective's recent activities, including the Drift and KelpDAO exploits, have resulted in losses exceeding $500 million over the past two weeks. Newson emphasized that the crypto industry must recognize Lazarus as a persistent and well-funded threat, rather than merely a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. This malware kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. The attack begins with an 'urgent' meeting invite sent to executives over Telegram, redirecting them to a convincing yet fake website that instructs them to copy and paste a command to 'fix a connection issue'. By doing so, victims inadvertently grant immediate access to corporate systems, SaaS platforms, and financial resources. The malware has several variations, and cases have been reported where Lazarus attackers have hijacked DeFI project domains, replacing their websites with fake messages that prompt victims to enter a command, thereby granting access. Traditional security controls often fail to detect this type of attack, as the page appears legitimate and the instructions seem normal, with the victim initiating the action themselves. Most victims remain unaware of the security breach until the damage has been done, and the malware has erased itself.