Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to turn ordinary business communications into a means of stealing credentials and sensitive data. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has been linked to the theft of over $500 million from the Drift and KelpDAO exploits, highlighting the need for the crypto industry to view Lazarus as a persistent and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by the group's Chollima division, which employs a social engineering technique known as ClickFix to trick victims into granting access to their systems. The attack involves sending fake meeting invites over Telegram, leading to a convincing but malicious website that instructs victims to paste a command into their terminal, thereby providing immediate access to corporate systems and financial resources. Variations of this attack have already been identified, with some cases involving the hijacking of decentralized finance project domains and the use of fake Cloudflare messages to trick victims into entering harmful commands.