Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data breaches. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is primarily targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective's activity level has significantly increased, with over $500 million siphoned from recent exploits. The crypto industry is advised to regard Lazarus as a persistent and well-funded threat, rather than just a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique has already been used to hijack DeFi project domains, replacing their websites with fake messages that instruct victims to enter a command, thereby granting access to the attackers. The malware often erases itself after a breach, making it challenging for victims to detect and identify the variant used in the attack.