Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK
Security experts have warned that the Lazarus Group's 'Mach-O Man' campaign poses a significant threat to fintech, cryptocurrency, and other high-value executives and firms. The group has been linked to cumulative losses of $6.7 billion since 2017 and has stolen over $500 million in the past two weeks alone. The Mach-O Man malware kit, developed by the group's Chollima division, uses a social engineering technique called ClickFix to trick victims into providing access to corporate systems and financial resources. The attack involves sending executives a fake meeting invite, which leads to a convincing website that instructs them to paste a command into their terminal to 'fix a connection issue.' By doing so, victims inadvertently grant immediate access to their systems, allowing the hackers to steal sensitive data and erase the malware, making it difficult to detect the breach.