Lazarus Group's New Mach-O Man Attack Poses Significant Threat
Security experts warn that the Lazarus Group's latest campaign, dubbed 'Mach-O Man,' enables the group to steal credentials and sensitive data by disguising malicious activity as ordinary business interactions. The group, which has amassed an estimated $6.7 billion in stolen funds since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level has increased significantly, with over $500 million stolen in the past two weeks alone. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to trick victims into granting access to their systems. The attack involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal, thereby providing immediate access to corporate systems and financial resources. Variations of this attack have already been identified, with some cases involving the hijacking of DeFi project domains and the use of fake Cloudflare messages to trick victims into entering harmful commands. The malware is designed to erase itself after a breach, making it difficult for victims to detect and identify the attack.