Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data loss. This campaign is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective has amassed an estimated $6.7 billion in cumulative loot since 2017. In recent weeks, the group has successfully siphoned over $500 million from the Drift and KelpDAO exploits, underscoring the sustained nature of their campaign. Newson emphasized that the crypto industry should regard Lazarus as a constant and well-funded threat, rather than merely another news headline. The Mach-O Man campaign is particularly concerning due to its modular macOS malware kit, which utilizes native Mach-O binaries tailored for Apple environments. This malware kit is being used in conjunction with a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. The attack begins with an 'urgent' meeting invite sent to executives over Telegram, which leads to a fake website that instructs them to copy and paste a command into their Mac's terminal. By doing so, the victims inadvertently provide immediate access to corporate systems, SaaS platforms, and financial resources. The malware is designed to erase itself after the damage has been done, making it challenging for victims to realize they have been breached and identify the specific variant of the attack that affected them.