Lazarus Group's Latest 'Mach-O Man' Attack Raises Alarm: CertiK

Security experts have warned about the North Korean state-sponsored Lazarus Group's latest campaign, dubbed 'Mach-O Man', which transforms ordinary business interactions into a conduit for credential theft and data breaches. The group has been targeting executives and companies in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, they have stolen over $500 million from exploits such as Drift and KelpDAO, demonstrating their sustained and well-funded campaign. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to trick victims into granting access to their systems. This technique involves sending fake meeting invites and instructing victims to paste a command into their terminal to 'fix a connection issue', ultimately providing the attackers with immediate access to corporate systems, SaaS platforms, and financial resources.