Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business communications into a direct route for credential theft and data loss. This campaign, targeting high-value executives and firms in the fintech and cryptocurrency sectors, has resulted in the theft of over $500 million in just two weeks. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level is what makes them particularly dangerous at this time, with multiple attacks, including the Drift and KelpDAO exploits, occurring within a short period. The Mach-O Man campaign utilizes a modular macOS malware kit created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to trick victims into providing access to corporate systems. The attack involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal, thereby granting immediate access to sensitive resources. By the time the victims realize they have been exploited, it is often too late, and the malware has already self-erased, making it challenging for them to identify the variant that affected them.