Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms everyday business interactions into a conduit for credential theft and data breaches. This campaign, orchestrated by the Lazarus Group, is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors, according to Natalie Newson, a senior blockchain security researcher at CertiK. With estimated cumulative loot of $6.7 billion since 2017, the group's activities have resulted in significant financial losses, including over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks alone. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just another news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. This malware kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. The attack begins with an 'urgent' meeting invite sent to executives over Telegram, leading to a fake website that instructs them to copy and paste a command to 'fix a connection issue', thereby providing immediate access to corporate systems, SaaS platforms, and financial resources. By the time the victims realize they have been exploited, it is often too late. The malware has several variations and can hijack decentralized finance (DeFi) projects' domains by replacing their websites with a fake message from Cloudflare, prompting victims to enter a command to grant access. Traditional security controls often miss this type of attack, as the page appears real and the instructions seem normal, with the victim initiating the action themselves. Most victims will not realize their security has been breached until the damage has been done, at which point the malware will have already erased itself.