Lazarus Group's Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency
Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to turn routine business communication into a direct path to credential theft and data loss. The group, responsible for an estimated $6.7 billion in loot since 2017, is targeting high-value executives and firms in the fintech, cryptocurrency, and other sectors. In the past two weeks alone, the North Korean hackers have siphoned over $500 million from the Drift and KelpDAO exploits, highlighting the sustained campaign. According to Natalie Newson, a senior blockchain security researcher at CertiK, what makes Lazarus especially dangerous is their high activity level, with multiple exploits and a new macOS malware kit all within the same month. The Mach-O Man campaign uses a modular macOS malware kit created by Lazarus Group's infamous Chollima division, which uses native Mach-O binaries tailored for Apple environments where crypto and fintech operate. The delivery method, known as ClickFix, involves a social engineering technique where the victim is asked to paste a command into their terminal to fix a simulated connection issue. The attack works by sending executives an 'urgent' meeting invite over Telegram for a Zoom, Microsoft Teams, or Google Meet call, which leads to a fake website that instructs them to copy and paste a command into their Mac's terminal to 'fix a connection issue'. This provides immediate access to corporate systems, SaaS platforms, and financial resources, often going undetected until it's too late. Variations of this attack have already been reported, with cases of Lazarus attackers hijacking DeFi projects' domains and replacing their websites with a fake message from Cloudflare, asking them to enter a command to grant access. The fake 'verification steps' guide victims through keyboard shortcuts that run a harmful command, often evading traditional security controls. Most victims will not realize their security has been breached until the damage has been done, at which point the malware will have already erased itself.