Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data breaches. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is primarily targeting high-value executives and firms in the fintech and cryptocurrency sectors, according to Natalie Newson, a senior blockchain security researcher at CertiK. In recent weeks, the North Korean hackers have successfully siphoned over $500 million from the Drift and KelpDAO exploits, underscoring the need for the crypto industry to regard Lazarus as a persistent and well-funded threat. The Mach-O Man malware kit, created by Lazarus' Chollima division, utilizes native Mach-O binaries tailored for Apple environments, where crypto and fintech operations are prevalent. The delivery method, known as ClickFix, involves a social engineering technique where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue, thereby granting immediate access to corporate systems, SaaS platforms, and financial resources. By the time victims realize they have been exploited, it is often too late, and the malware has already self-erased.