Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business interactions into a direct pathway for credential theft and data loss. The Lazarus Group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level is particularly alarming, with over $500 million siphoned from the Drift and KelpDAO exploits in just two weeks. The crypto industry is urged to view Lazarus as a constant and well-funded threat, rather than just a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to deliver the malware. This technique involves convincing victims to paste a command into their terminal to resolve a simulated connection issue, thereby granting immediate access to corporate systems, SaaS platforms, and financial resources. The attack is often successful due to its convincing nature, with the malware erasing itself after the damage is done, leaving most victims unaware of the breach.