Lazarus Group's Mach-O Man Attack Poses Significant Threat to Crypto and Fintech Industries
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a direct route for credential theft and data loss. The Lazarus Group, a state-run collective with estimated cumulative loot of $6.7 billion since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained campaign. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the creation of a new macOS malware kit, has increased significantly. This malware kit, also known as Mach-O Man, is a modular macOS malware kit developed by Lazarus Group's Chollima division, utilizing native Mach-O binaries tailored for Apple environments. The kit employs a delivery method known as ClickFix, a social engineering technique where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. The attack begins with an 'urgent' meeting invite sent to executives over Telegram, leading to a fake website that instructs them to copy and paste a command to 'fix a connection issue', thereby granting immediate access to corporate systems, SaaS platforms, and financial resources. By the time the victims realize they have been exploited, it is often too late. Several variations of this attack have been identified, and cases have been reported where Lazarus attackers have hijacked DeFI projects' domains using this new malware, replacing their websites with fake messages from Cloudflare. The fake 'verification steps' guide victims through keyboard shortcuts that execute a harmful command, often evading traditional security controls. Most victims will not realize their security has been breached until the damage has been done, and the malware will have already erased itself.