Lazarus Group Poses Enhanced Threat with Mach-O Man Attack, Warns CertiK
Security experts have sounded the alarm over the Lazarus Group's latest campaign, dubbed 'Mach-O Man,' which transforms ordinary business interactions into a conduit for credential theft and data compromise. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors. With estimated cumulative loot of $6.7 billion since 2017, the collective has siphoned over $500 million in the past two weeks alone from the Drift and KelpDAO exploits. Newson emphasizes that the crypto industry must regard Lazarus as a persistent and well-funded threat, rather than merely a news headline. The Mach-O Man campaign is characterized by its use of a modular macOS malware kit, created by Lazarus' infamous Chollima division, which utilizes native Mach-O binaries tailored for Apple environments. This malware kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. The attack begins with an 'urgent' meeting invite sent to executives over Telegram, directing them to a fake website that instructs them to copy and paste a command into their Mac's terminal. By doing so, victims unwittingly grant immediate access to corporate systems, SaaS platforms, and financial resources. The malware is designed to erase itself after a breach, leaving most victims unaware of the security compromise until the damage has been done.