Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat to Crypto and Fintech
Security experts have warned of a new campaign, known as 'Mach-O Man', which transforms ordinary business interactions into a conduit for credential theft and data loss. This campaign, run by the North Korean state-sponsored Lazarus Group, targets high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective has amassed an estimated $6.7 billion since 2017. In recent weeks, the group has stolen over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. The crypto industry is urged to view Lazarus as a constant and significant threat, rather than just a news headline. The group's activity level, including the release of a new macOS malware kit, has increased significantly. This modular kit, created by Lazarus' Chollima division, uses native Mach-O binaries tailored for Apple environments and employs a social engineering technique known as ClickFix. The attack begins with an 'urgent' meeting invite sent to executives over Telegram, leading to a fake website that instructs victims to paste a command into their terminal to 'fix a connection issue', thereby granting immediate access to corporate systems and financial resources. By the time the victims discover they have been exploited, it is often too late. Variations of this attack have already been identified, with cases of Lazarus attackers hijacking DeFI project domains and replacing their websites with fake messages. The malware is designed to erase itself after the damage has been done, leaving most victims unaware of the breach until it is too late.