Lazarus Group's Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency Firms
Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to transform ordinary business communications into a direct route for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has successfully siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained and well-funded campaign. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to deceive victims into granting access to corporate systems. The attack involves sending 'urgent' meeting invites over Telegram, leading to a fake website that instructs victims to copy and paste a command into their Mac's terminal to 'fix a connection issue', thereby providing immediate access to sensitive resources. By the time victims discover they have been exploited, it is often too late, and the malware has already self-erased. The crypto industry is advised to regard Lazarus as a constant and well-funded threat, rather than just another news headline, due to their elevated activity level and state-directed financial operations.