Lazarus Group's Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to transform ordinary business communications into a conduit for credential theft and data compromise. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is primarily targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective's activity level has significantly increased, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks alone. Newson emphasized that the crypto industry should regard Lazarus as a persistent and well-funded threat, rather than merely a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. This malware kit is being used by other cybercrime groups, in addition to Lazarus. The delivery method, known as ClickFix, involves a social engineering technique where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique has been used to target executives with 'urgent' meeting invites over Telegram, leading to fake websites that instruct victims to copy and paste a command, thereby granting immediate access to corporate systems, SaaS platforms, and financial resources. By the time the victims discover they have been exploited, it is often too late. There are multiple variations of this attack, and cases have been reported where Lazarus attackers have hijacked DeFI projects' domains using this new malware, replacing their websites with fake messages from Cloudflare. The fake 'verification steps' guide victims through keyboard shortcuts that execute a harmful command, often evading traditional security controls. Most victims will not realize their security has been breached until the damage has been done, at which point the malware will have already self-erased.