Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat to Crypto and Fintech Firms
Security experts have warned that the Lazarus Group, a notorious North Korean state-run hacking collective, has launched a new campaign known as 'Mach-O Man', which transforms ordinary business communications into a direct pathway to credential theft and data loss. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group has set its sights on high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the hackers have stolen over $500 million from the Drift and KelpDAO exploits, highlighting the sustained nature of their campaign. Newson emphasized that the crypto industry must view Lazarus as a constant and well-funded threat, rather than just another news headline. The Mach-O Man attack utilizes a modular macOS malware kit created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The malware is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. This technique has already been used to hijack decentralized finance (DeFi) projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The attack is particularly dangerous due to its ability to evade traditional security controls, with most victims unlikely to realize their security has been breached until the damage has been done.