Lazarus Group's Latest Mach-O Man Attack Raises Alarm: CertiK
Security researchers have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a conduit for credential theft and data loss. The Lazarus Group, a state-sponsored collective, has been targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained campaign. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the creation of a new macOS malware kit, has raised concerns among security experts. The Mach-O Man malware kit, developed by Lazarus' Chollima division, uses native Mach-O binaries tailored for Apple environments and employs a social engineering technique known as ClickFix. This technique involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal, thereby granting immediate access to corporate systems and financial resources. Variations of this attack have already been identified, with some cases involving the hijacking of decentralized finance project domains. The malware often erases itself after a breach, making it challenging for victims to realize they have been compromised and identify the variant used.