Lazarus Group's Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency
Security experts have warned of a new campaign by the North Korean state-run Lazarus Group, known as 'Mach-O Man', which transforms routine business communication into a direct pathway for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech, cryptocurrency, and other sectors. In recent weeks, they have siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained campaign. According to Natalie Newson, a senior blockchain security researcher at CertiK, the crypto industry must view Lazarus as a constant and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to 'fix a connection issue'. This allows the attackers to gain immediate access to corporate systems, SaaS platforms, and financial resources. The attack is often missed by traditional security controls, and by the time victims realize they have been exploited, it is usually too late. The malware erases itself after the damage is done, making it challenging for victims to identify which variant affected them.