Lazarus Group Intensifies Threat with Mach-O Man Attack
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business interactions into a gateway for credential theft and data loss. The Lazarus Group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's recent activities, including the Drift and KelpDAO exploits, have resulted in the theft of over $500 million in just two weeks. Newson emphasized that the crypto industry should view Lazarus as a persistent and well-funded threat, rather than just a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to trick victims into providing access to corporate systems. The attack involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal to fix a connection issue, thereby granting immediate access to sensitive resources. Variations of this attack have already been reported, with some cases involving the hijacking of DeFi project domains and the use of fake Cloudflare messages to trick victims into running harmful commands. The malware is designed to erase itself after the attack, making it challenging for victims to detect and identify the breach.