Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which enables the Lazarus Group to transform ordinary business communications into a conduit for credential theft and data compromise. This state-sponsored collective, responsible for an estimated $6.7 billion in cumulative losses since 2017, is primarily targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's recent activities, including the Drift and KelpDAO exploits, have resulted in the theft of over $500 million in the past two weeks alone. Newson emphasized that the crypto industry must perceive Lazarus as a persistent and well-funded threat, rather than merely a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. This malware kit is being used not only by Lazarus but also by other cybercrime groups. The delivery method, known as ClickFix, involves social engineering, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique allows the attackers to gain immediate access to corporate systems, SaaS platforms, and financial resources. The attack is often disguised as an 'urgent' meeting invite over Telegram, leading to a fake website that instructs victims to copy and paste a command into their Mac's terminal. By the time the victims realize they have been exploited, it is usually too late, and the malware has already self-erased. The victims often remain unaware of the breach until the damage has been done, and even then, they may struggle to identify which variant of the attack affected them.