Lazarus Group's New Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency

Security experts have warned of a new campaign, known as 'Mach-O Man', being conducted by the North Korean state-run Lazarus Group, which transforms ordinary business communication into a direct pathway to credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech, cryptocurrency, and other sectors. In recent weeks, the group has successfully siphoned over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just another news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique has been used to hijack decentralized finance (DeFi) projects' domains, replacing their websites with fake messages from Cloudflare, and asking victims to enter a command to grant access. The attack is particularly dangerous, as it often goes undetected by traditional security controls, and the malware erases itself after the damage has been done, leaving victims unaware of the breach.