Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency
Security experts have warned of a new campaign by the Lazarus Group, a state-run collective from North Korea, which has been estimated to have amassed $6.7 billion in cumulative loot since 2017. The group's latest attack, dubbed Mach-O Man, involves using routine business calls as a gateway to exploit targets' systems, with a focus on fintech, cryptocurrency, and high-value executives and firms. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group has siphoned over $500 million in the past two weeks alone from the Drift and KelpDAO exploits, demonstrating a sustained campaign. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just a news headline. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which uses native Mach-O binaries tailored for Apple environments where crypto and fintech operate. The kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. This technique has already been used to hijack decentralized finance (DeFI) projects' domains, replacing their websites with fake messages from Cloudflare, and instructing victims to enter a command to grant access. The attack is particularly dangerous, as it allows Lazarus to gain immediate access to corporate systems, SaaS platforms, and financial resources, often without the victim's knowledge until it's too late.