Lazarus Group's Mach-O Man Attack: A New Threat to Business Security
Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the North Korean hackers have stolen over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. The crypto industry is advised to view Lazarus as a constant and serious threat, rather than just a news headline. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The delivery method, known as ClickFix, involves social engineering, where victims are tricked into pasting a command into their terminal to 'fix' a simulated connection issue. This technique has already been used to hijack decentralized finance (DeFi) projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The attack is particularly dangerous, as it often goes undetected until the damage has been done, and the malware has erased itself.