Lazarus Group's Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which enables the Lazarus Group to turn ordinary business communications into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the hackers have stolen over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained and well-funded campaign. The Mach-O Man malware kit, created by Lazarus' Chollima division, utilizes native Mach-O binaries tailored for Apple environments and employs a social engineering technique known as ClickFix to deliver the malware. This technique involves convincing victims to paste a command into their terminal to 'fix a connection issue,' thereby granting immediate access to corporate systems and financial resources. The attack is often undetectable until the damage has been done, and the malware has self-erased.