Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK
Security researchers have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to turn routine business communications into a means of stealing credentials and sensitive data. The group, which has amassed an estimated $6.7 billion since 2017, is primarily targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has been linked to the theft of over $500 million from the Drift and KelpDAO exploits, highlighting the sustained nature of their campaign. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which is tailored for Apple environments where crypto and fintech operations are prevalent. The kit employs a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique allows the attackers to gain immediate access to corporate systems, SaaS platforms, and financial resources. The attack is often disguised as an urgent meeting invite over Telegram, leading to a fake website that instructs victims to copy and paste a command into their Mac's terminal. By the time the victims realize they have been exploited, it is usually too late, and the malware has already self-erased. The lack of awareness among victims and the ability of the malware to erase itself make it challenging to identify and track the attack. As a result, security experts are urging the crypto industry to view the Lazarus Group as a constant and well-funded threat, rather than just a news headline.