Lazarus Group's Mach-O Man Attack Elevates Threat Level: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a direct conduit for credential theft and data loss. The group, known for its state-run operations, has been targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level has made it especially dangerous, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The malware is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to 'fix a connection issue'. This technique allows the attackers to gain immediate access to corporate systems, SaaS platforms, and financial resources. Variations of this attack have been reported, with some cases involving the hijacking of decentralized finance (DeFi) projects' domains, replacing their websites with fake messages from Cloudflare. The malware often erases itself after the damage has been done, making it difficult for victims to realize their security has been breached and identify which variant affected them.