Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business interactions into a conduit for credential theft and data loss. The Lazarus Group, known for its state-sponsored cyberattacks, is targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has stolen over $500 million from the Drift and KelpDAO exploits, demonstrating its sustained and well-funded threat to the crypto industry. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to trick victims into granting access to corporate systems and financial resources. The attack involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal, thereby providing immediate access to sensitive information. With its ability to erase itself after a breach, the malware often goes undetected, leaving victims unaware of the damage until it's too late.