Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which enables the Lazarus Group to transform ordinary business communications into a conduit for credential theft and data loss. The group, estimated to have amassed $6.7 billion since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level has increased significantly, with over $500 million siphoned from recent exploits. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to trick victims into providing access to corporate systems. The attack involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal, thereby granting immediate access to sensitive resources. Variations of this attack have already been identified, with some cases involving the hijacking of decentralized finance project domains. The malware often erases itself after a breach, making it challenging for victims to detect and identify the specific variant used.