Lazarus Group's New Mach-O Man Attack Poses Significant Threat
Security experts have warned of a new campaign, known as 'Mach-O Man,' being conducted by the North Korean state-run Lazarus Group, which transforms ordinary business communication into a direct pathway for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has successfully siphoned over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained campaign. According to Natalie Newson, a senior blockchain security researcher at CertiK, the crypto industry must view Lazarus as a constant and well-funded threat. The group's activity level, including the KelpDAO, Drift, and a new macOS malware kit, all within the same month, underscores the scale and speed typical of institutions. North Korea has established crypto theft as a lucrative national industry, with Mach-O Man being the latest product of this process. The modular macOS malware kit, created by Lazarus Group's Chollima division, utilizes native Mach-O binaries tailored for Apple environments where crypto and fintech operate. The delivery method, known as ClickFix, involves a social engineering technique where the victim is instructed to paste a command into their terminal to resolve a simulated connection issue. This technique has been used to target executives with 'urgent' meeting invites over Telegram, leading to a fake website that requests the victim to copy and paste a command into their Mac's terminal, thereby granting immediate access to corporate systems, SaaS platforms, and financial resources. The attack often goes undetected until the damage has been done, at which point the malware erases itself. Variations of this attack have already been identified, with some cases involving the hijacking of decentralized finance (DeFI) projects' domains, replacing their websites with fake messages from Cloudflare, and prompting victims to enter a command to grant access.