Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK

Security experts have warned of a new campaign, known as 'Mach-O Man,' which transforms ordinary business interactions into a conduit for credential theft and data loss. The Lazarus Group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has stolen over $500 million from Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. This malware kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. The attack begins with an 'urgent' meeting invite sent to executives over Telegram, leading to a fake website that instructs them to copy and paste a command into their Mac's terminal. By doing so, victims inadvertently provide immediate access to corporate systems, SaaS platforms, and financial resources. The malware often erases itself after the damage is done, leaving most victims unaware of the breach until it's too late.