Lazarus Group's Mach-O Man Attack Intensifies Threat Landscape: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business communications into a direct conduit for credential theft and data compromise. The group, known for its state-sponsored cyber activities, has been targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective has stolen over $500 million in the past two weeks alone, highlighting the need for the crypto industry to regard Lazarus as a persistent and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to deceive victims into granting access to corporate systems and financial resources. The attack involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal, thereby providing immediate access to sensitive information. With several variations of this attack already identified, security experts stress that traditional security controls often fail to detect these threats, and most victims remain unaware of the breach until the damage is done.