Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK Warns

Security experts have alerted to a new campaign, 'Mach-O Man', executed by the North Korean state-sponsored Lazarus Group, which converts ordinary business communications into a direct route for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors, according to Natalie Newson, a senior blockchain security researcher at CertiK. In the past two weeks, the group has stolen over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained campaign. Newson emphasizes that the crypto industry must perceive Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the KelpDAO, Drift, and a new macOS malware kit, all within the same month, signifies a state-directed financial operation. North Korea has established crypto theft as a lucrative national industry, with Mach-O Man being the latest product. The malware kit, created by Lazarus' Chollima division, utilizes native Mach-O binaries tailored for Apple environments, where crypto and fintech operate. It employs a social engineering technique known as ClickFix, where victims are instructed to paste a command into their terminal to resolve a simulated connection issue. This technique allows Lazarus to send executives 'urgent' meeting invites, leading to a fake website that requests them to copy and paste a command, granting immediate access to corporate systems and financial resources. The attack often goes undetected until the damage is done, and the malware has erased itself.