Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to turn ordinary business interactions into a pathway for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the hackers have stolen over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which is tailored for Apple environments and employs a social engineering technique known as ClickFix. This involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal, thereby granting immediate access to corporate systems and financial resources. By the time victims realize they have been exploited, it is often too late, and the malware has already self-erased. The attack's success can be attributed to its ability to circumvent traditional security controls, with most victims remaining unaware of the breach until the damage has been done.