Lazarus Group's Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the North Korean state-run Lazarus Group to transform ordinary business communications into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors, according to Natalie Newson, a senior blockchain security researcher at CertiK. Over the past two weeks, the group has siphoned off over $500 million from the Drift and KelpDAO exploits, underscoring the need for the crypto industry to view Lazarus as a persistent and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' infamous Chollima division, which employs native Mach-O binaries tailored for Apple environments. This malware kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. The attack begins with an 'urgent' meeting invite sent over Telegram, leading to a fake website that instructs victims to copy and paste a command to 'fix a connection issue', thereby granting immediate access to corporate systems, SaaS platforms, and financial resources. By the time victims realize they have been exploited, it is often too late, and the malware has already self-erased. The attack's success can be attributed to its ability to evade traditional security controls, with most victims unaware of the breach until the damage has been done.