Lazarus Group's Latest Mach-O Man Attack Puts Crypto and Fintech at Risk: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to turn routine business communication into a pathway for credential theft and data loss. This state-run collective has been targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained campaign. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the creation of a new macOS malware kit, has made it especially dangerous. This malware kit, developed by Lazarus' Chollima division, uses native Mach-O binaries tailored for Apple environments, where crypto and fintech operate. The delivery method, known as ClickFix, involves social engineering, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. This technique has already been used to hijack DeFI projects' domains, replacing their websites with fake messages that ask users to enter a command to grant access. The malware is designed to erase itself after the damage has been done, making it difficult for victims to realize they have been breached.