Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective's activity level is particularly alarming, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks alone. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to trick victims into providing access to corporate systems and financial resources. The attack involves sending executives 'urgent' meeting invites over Telegram, leading them to a fake website that instructs them to copy and paste a command into their Mac's terminal to 'fix a connection issue.' By the time victims realize they have been exploited, it is often too late, and the malware has already erased itself.