Lazarus Group's New Mach-O Man Attack: A Growing Threat to Crypto and Fintech

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a direct route for credential theft and data loss. The campaign, attributed to North Korea's state-run Lazarus Group, has already resulted in the theft of over $500 million in the past two weeks alone. The group's activity level has been deemed especially dangerous, with a sustained campaign targeting fintech, cryptocurrency, and other high-value executives and firms. The Mach-O Man malware kit, created by Lazarus' infamous Chollima division, uses a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to 'fix a connection issue', thereby granting immediate access to corporate systems, SaaS platforms, and financial resources. The attack has several variations, and most victims will not realize their security has been breached until the damage has been done, at which point the malware will have already erased itself.