Lazarus Group Intensifies Threat with Mach-O Man Attack, Warns CertiK

Security experts have alerted the public to a new campaign by the Lazarus Group, dubbed 'Mach-O Man', which transforms ordinary business interactions into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors, according to Natalie Newson, a senior blockchain security researcher at CertiK. In recent weeks, the group has siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained campaign. Newson emphasized that the crypto industry must view Lazarus as a persistent and well-funded threat, rather than just a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs native Mach-O binaries tailored for Apple environments. The kit is delivered through a social engineering technique known as ClickFix, where victims are deceived into pasting a command into their terminal to resolve a simulated connection issue. This technique has already been used to hijack DeFI project domains, replacing websites with fake messages that instruct victims to enter a command, thereby granting access to the attackers. The malware often erases itself after a breach, leaving victims unaware of the security compromise until it's too late.