Lazarus Group's Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency Firms
Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the North Korean hackers have stolen over $500 million from exploits such as Drift and KelpDAO, highlighting the sustained nature of their campaign. According to Natalie Newson, a senior blockchain security researcher at CertiK, the crypto industry must recognize Lazarus as a constant and well-funded threat. The group's activity level, including the development of a new macOS malware kit, has raised concerns about the scale and speed of their operations. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs native Mach-O binaries tailored for Apple environments. The kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique has already been used to hijack DeFI projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The attack is particularly stealthy, as the malware erases itself after the damage has been done, leaving most victims unaware of the breach.