Lazarus Group's Mach-O Man Attack Poses Significant Threat to Crypto and Fintech Firms

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a direct route for credential theft and data loss. The Lazarus Group, a state-run collective, is behind this campaign, targeting high-value executives and firms in the fintech and cryptocurrency sectors. With estimated cumulative loot of $6.7 billion since 2017, the group has siphoned over $500 million in the past two weeks alone from the Drift and KelpDAO exploits. According to Natalie Newson, a senior blockchain security researcher at CertiK, the crypto industry must view Lazarus as a constant and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The delivery method, known as ClickFix, involves a social engineering technique where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. This technique has already been used to hijack decentralized finance (DeFi) projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The malware erases itself after the damage is done, making it challenging for victims to realize they have been breached and identify the variant that affected them.