Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, known as 'Mach-O Man', which transforms ordinary business interactions into a conduit for credential theft and data loss. The Lazarus Group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech, cryptocurrency, and other industries. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level is particularly concerning, with over $500 million siphoned from recent exploits. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to trick victims into providing access to corporate systems. The attack involves sending 'urgent' meeting invites, leading to a fake website that instructs victims to paste a command into their terminal, thereby granting immediate access to sensitive resources. Variations of this attack have already been reported, with some cases involving the hijacking of DeFi projects' domains. The malware often erases itself after a breach, making it difficult for victims to detect and identify the variant used.