Lazarus Group's Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business interactions into a conduit for credential theft and data loss. The Lazarus Group, a state-run collective with estimated cumulative loot of $6.7 billion since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group has siphoned over $500 million in the past two weeks alone from the Drift and KelpDAO exploits. The crypto industry is advised to view Lazarus as a constant and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix. This technique involves sending executives 'urgent' meeting invites, leading them to a fake website that instructs them to paste a command into their terminal to 'fix a connection issue', thereby granting immediate access to corporate systems and financial resources. Variations of this attack have already been observed, with some cases involving the hijacking of decentralized finance project domains. The malware is designed to erase itself after a breach, making it challenging for victims to detect and identify the attack.