Lazarus Group's New Mach-O Man Attack Poses Significant Threat
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to turn ordinary business interactions into a conduit for credential theft and data breaches. The group, known for its state-sponsored hacking activities, has been targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has been linked to the theft of over $500 million from the Drift and KelpDAO exploits. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to trick victims into granting access to their systems. The attack involves sending fake meeting invites, leading to a convincing website that instructs victims to paste a command into their terminal, thereby providing immediate access to corporate systems and financial resources. The malware is highly sophisticated, often erasing itself after a breach, leaving most victims unaware of the attack until the damage has been done.