Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to turn ordinary business interactions into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level has increased significantly, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks. The Mach-O Man campaign involves a modular macOS malware kit, created by Lazarus Group's Chollima division, which uses native Mach-O binaries tailored for Apple environments. The kit is delivered via a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. This technique has already been used to hijack decentralized finance (DeFi) projects' domains, with victims unknowingly providing access to corporate systems, SaaS platforms, and financial resources. The malware is designed to erase itself after a breach, making it difficult for victims to detect and identify the attack.