Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a direct pathway for credential theft and data breaches. The group, estimated to have accumulated $6.7 billion in stolen funds since 2017, is primarily targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has successfully siphoned over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-organized campaign. According to Natalie Newson, a senior blockchain security researcher at CertiK, the Lazarus Group's heightened activity level and state-directed financial operations pose a significant threat to the crypto industry. The Mach-O Man malware kit, created by the group's Chollima division, utilizes a modular approach and native Mach-O binaries tailored for Apple environments, where crypto and fintech operations are prevalent. The malware is delivered through a social engineering technique known as ClickFix, which involves convincing victims to paste a command into their terminal to resolve a simulated connection issue. This technique has already been used to hijack DeFI project domains, replacing their websites with fake messages that instruct victims to enter a command, thereby granting access to the attackers. The attack is particularly insidious, as it often goes undetected until the damage has been done, and the malware has self-erased, leaving victims unaware of the breach.