Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data loss. The group, known for its state-sponsored cyber activities, has been targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective has amassed an estimated $6.7 billion in loot since 2017. In recent weeks, the group has successfully siphoned over $500 million from the Drift and KelpDAO exploits, demonstrating its sustained campaign. Newson emphasized that the crypto industry must view Lazarus as a constant and well-funded threat, rather than just another news headline. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to 'fix' a simulated connection issue. This technique has already been used to hijack decentralized finance (DeFi) projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The attack is particularly dangerous due to its ability to evade traditional security controls, with most victims remaining unaware of the breach until the damage has been done.