Lazarus Group's Mach-O Man Attack Elevates Threat Level: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data breaches. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the hackers have stolen over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. The Mach-O Man attack utilizes a modular macOS malware kit, created by the Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The malware is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This approach allows the attackers to gain immediate access to corporate systems, SaaS platforms, and financial resources. The attack's success can be attributed to its ability to evade traditional security controls, with most victims remaining unaware of the breach until the damage has been done.