Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK Warning
Security experts have sounded the alarm over a novel campaign, dubbed 'Mach-O Man,' which transforms ordinary business communications into a conduit for credential theft and data loss. The Lazarus Group, a state-run collective with estimated cumulative loot of $6.7 billion since 2017, is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level has escalated, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks alone. The crypto industry is advised to regard Lazarus as a constant and well-funded threat, rather than merely another news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The kit is delivered via a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique has already been used to hijack decentralized finance (DeFi) projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The attack is particularly stealthy, as the malware erases itself after the damage has been done, leaving most victims unaware of the breach until it's too late.