Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the North Korean state-run Lazarus Group to steal credentials and sensitive data by disguising malicious activity as ordinary business interactions. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group has been targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has successfully stolen over $500 million through the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. Newson emphasized that the group's activity level and state-directed financial operations pose a significant threat to the crypto industry, which should view Lazarus as a constant and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to deliver the malware. This technique involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal, thereby granting immediate access to corporate systems and financial resources. The attack is often successful due to its ability to bypass traditional security controls, with most victims remaining unaware of the breach until the damage has been done.