Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK
Security experts have warned of a new campaign by the North Korean state-run Lazarus Group, known as 'Mach-O Man', which transforms ordinary business interactions into a direct pathway for credential theft and data loss. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has successfully siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained and well-funded campaign. Newson emphasizes that the crypto industry must recognize Lazarus as a constant and well-funded threat, rather than just a news headline. The group's latest malware kit, Mach-O Man, is a modular macOS kit created by the infamous Chollima division, utilizing native Mach-O binaries tailored for Apple environments commonly used in crypto and fintech. This kit employs a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue, thereby granting immediate access to corporate systems and financial resources. Variations of this attack have already been identified, with cases of Lazarus attackers hijacking DeFI project domains and replacing websites with fake messages that instruct victims to enter commands, allowing the malware to erase itself after the damage is done, leaving most victims unaware of the breach.