Lazarus Group's Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to turn ordinary business interactions into a conduit for credential theft and data loss. The group, backed by the North Korean state, has been targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has stolen over $500 million from the Drift and KelpDAO exploits, demonstrating its sustained campaign. According to Natalie Newson, a senior blockchain security researcher at CertiK, the crypto industry must view Lazarus as a constant and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs native Mach-O binaries tailored for Apple environments. The delivery method, known as ClickFix, involves social engineering, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique has been used to hijack DeFI projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The attack is highly sophisticated, with most victims unaware of the breach until the damage is done, and the malware has self-erased.