Lazarus Group's New Mach-O Man Attack Poses Significant Threat
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a conduit for credential theft and data loss. The Lazarus Group, a state-run collective with estimated cumulative loot of $6.7 billion since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has stolen over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained campaign. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the creation of a new macOS malware kit, has made it particularly dangerous. The Mach-O Man campaign utilizes a modular macOS malware kit, tailored for Apple environments, and employs a social engineering technique known as ClickFix. This involves sending executives 'urgent' meeting invites, leading to a fake website that instructs them to paste a command into their terminal, thereby granting access to corporate systems and financial resources. The attack often goes undetected until it's too late, with the malware erasing itself after the damage is done.