Lazarus Group Unleashes Devastating Mach-O Man Attack, Warns CertiK

Security experts have sounded the alarm over a new campaign, dubbed 'Mach-O Man,' which transforms ordinary business communication into a conduit for credential theft and data loss. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective has set its sights on high-value targets in the fintech, cryptocurrency, and executive sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has successfully siphoned over $500 million from the Drift and KelpDAO exploits, underscoring the need for the crypto industry to regard Lazarus as a persistent and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to trick victims into granting access to corporate systems. This sophisticated attack has already been used to hijack DeFi project domains, with victims often remaining unaware of the security breach until the damage is done.