Lazarus Group Intensifies Threat with Mach-O Man Attack, Warns CertiK

Security experts have identified a new campaign, known as 'Mach-O Man', by the North Korean state-run Lazarus Group, which converts ordinary business communications into a direct route for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective has siphoned over $500 million in the past two weeks alone from the Drift and KelpDAO exploits, marking a sustained campaign. Newson emphasizes that the crypto industry should view Lazarus as a constant and well-funded threat, rather than just another news headline. The Mach-O Man campaign is particularly alarming due to its scale and speed, which is typical of institutional operations. The campaign utilizes a modular macOS malware kit created by Lazarus Group's Chollima division, tailored for Apple environments where crypto and fintech operate. The malware kit employs a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. This technique allows Lazarus to gain immediate access to corporate systems, SaaS platforms, and financial resources. The attack is often successful because it appears as a legitimate connection issue, and by the time victims realize they have been exploited, it is usually too late. There are several variations of this attack, and security threat researcher Vladimir S. notes that there are already cases where Lazarus attackers have hijacked DeFI projects' domains using this new malware. The fake 'verification steps' guide victims through keyboard shortcuts that run a harmful command, often evading traditional security controls. Most victims will not realize their security has been breached until the damage has been done, at which point the malware will have already erased itself.