Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business communications into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors, according to Natalie Newson, a senior blockchain security researcher at CertiK. In recent weeks, the North Korean hackers have stolen over $500 million from exploits such as Drift and KelpDAO, underscoring the need for the crypto industry to regard Lazarus as a persistent and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. This malware kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. The attack begins with an 'urgent' meeting invite sent to executives over Telegram, redirecting them to a fake website that instructs them to copy and paste a command into their Mac's terminal. By doing so, victims inadvertently grant immediate access to corporate systems, SaaS platforms, and financial resources. The malware is designed to erase itself after the damage is done, leaving most victims unaware of the security breach until it's too late.