Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the North Korean state-run Lazarus Group to transform ordinary business communication into a conduit for credential theft and data loss. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective has amassed an estimated $6.7 billion since 2017 and is currently targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has successfully siphoned over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. Newson emphasized that the crypto industry must view Lazarus as a constant and well-funded threat, rather than just another news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The malware is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique has been used to infiltrate corporate systems, SaaS platforms, and financial resources, often going undetected until the damage has been done. Variations of this attack have already been identified, with some cases involving the hijacking of decentralized finance (DeFI) projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The fake 'verification steps' guide victims through keyboard shortcuts that execute a harmful command, often evading traditional security controls. As a result, most victims are unlikely to realize their security has been breached until the damage has been done, at which point the malware will have already erased itself.