Lazarus Group Intensifies Threat with Mach-O Man Attack, Warns CertiK
Security researchers at CertiK have alerted the public to a new campaign, dubbed 'Mach-O Man', orchestrated by the North Korean state-sponsored Lazarus Group. This campaign transforms ordinary business communications into a conduit for credential theft and data loss. The group, known for its extensive loot of $6.7 billion since 2017, is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, Lazarus has successfully siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs native Mach-O binaries tailored for Apple environments. This malware is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. The attack begins with an 'urgent' meeting invite sent to executives over Telegram, redirecting them to a fake website that instructs them to copy and paste a command to 'fix a connection issue', thereby granting immediate access to corporate systems and financial resources. By the time the exploit is discovered, the damage is often irreparable. Variations of this attack have already been identified, with instances of Lazarus hijacking DeFi project domains and replacing their websites with fake Cloudflare messages that prompt victims to enter a command, effectively initiating a harmful action. The Mach-O Man campaign's sophistication and the group's elevated activity level have prompted warnings that the crypto industry must view Lazarus as a constant and well-funded threat, rather than merely another news headline.