Lazarus Group's Mach-O Man Attack Elevates Threat Level: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man,' where the Lazarus Group transforms ordinary business communications into a direct pathway for stealing sensitive information and compromising data. This state-run collective, responsible for an estimated $6.7 billion in cumulative losses since 2017, is now targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level has significantly increased, with over $500 million siphoned from the Drift and KelpDAO exploits in just two weeks. Newson emphasized that the crypto industry must view Lazarus as a constant and well-funded threat, rather than just another news headline. The Mach-O Man campaign is characterized by its use of a modular macOS malware kit, created by Lazarus Group's infamous Chollima division, which utilizes native Mach-O binaries tailored for Apple environments where crypto and fintech operate. This malware kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to 'fix a connection issue.' The attack begins with an 'urgent' meeting invite sent to executives over Telegram, leading to a fake website that instructs them to copy and paste a command, thereby granting immediate access to corporate systems, SaaS platforms, and financial resources. By the time the victims realize they have been exploited, it is often too late. Variations of this attack have already been identified, with cases where Lazarus attackers have hijacked DeFi projects' domains, replacing their websites with fake messages that ask victims to enter a command to grant access. The malware is designed to erase itself after a breach, making it challenging for victims to identify which variant affected them.