Lazarus Group's Mach-O Man Attack: A New Threat to Business Security
Security researchers at CertiK have warned of a new campaign by the Lazarus Group, known as 'Mach-O Man', which transforms ordinary business communications into a conduit for credential theft and data compromise. This campaign targets high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has been linked to the theft of over $500 million from the Drift and KelpDAO exploits. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which is tailored for Apple environments commonly used in the crypto and fintech industries. The malware is delivered through a social engineering technique called ClickFix, where victims are tricked into pasting a command into their terminal to 'fix' a simulated connection issue. This technique allows the attackers to gain immediate access to corporate systems, SaaS platforms, and financial resources. The attack is particularly dangerous due to its ability to evade traditional security controls, with most victims remaining unaware of the breach until the damage has been done.