Lazarus Group's Mach-O Man Attack Poses Significant Threat to Crypto and Fintech Firms
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data compromise. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group has set its sights on high-value executives and firms in the fintech and cryptocurrency sectors. With estimated cumulative loot of $6.7 billion since 2017, the collective has demonstrated its capabilities in recent exploits, including the theft of over $500 million from Drift and KelpDAO in the past two weeks. Newson emphasized that the crypto industry must acknowledge the Lazarus Group as a persistent and well-funded threat, rather than simply a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. This malware kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. The attack begins with an 'urgent' meeting invite sent to executives over Telegram, which leads to a fake website instructing them to copy and paste a command into their Mac's terminal. By doing so, victims inadvertently grant immediate access to corporate systems, SaaS platforms, and financial resources. The malware has several variations, and in some cases, Lazarus attackers have hijacked DeFi project domains by replacing their websites with a fake message from Cloudflare, prompting victims to enter a command to grant access. The fake 'verification steps' guide victims through keyboard shortcuts that execute a harmful command, often evading traditional security controls. Most victims remain unaware of the breach until the damage is done, at which point the malware has already self-erased.