Lazarus Group's Latest Mach-O Man Attack: A Growing Threat to Cryptocurrency and Fintech
Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the North Korean state-run Lazarus Group to transform ordinary business interactions into a direct pathway for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has successfully siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained and well-funded campaign. The 'Mach-O Man' attack utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique called ClickFix to trick victims into granting access to their systems. This technique involves sending fake meeting invites, leading to a convincing website that instructs victims to paste a command into their terminal, thereby providing immediate access to corporate resources. The attack is particularly dangerous due to its ability to evade traditional security controls, with most victims remaining unaware of the breach until the damage has been done.