Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a direct route for credential theft and data loss. This state-sponsored collective, responsible for an estimated $6.7 billion in cumulative losses since 2017, is primarily targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level has increased significantly, with over $500 million siphoned from recent exploits. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to trick victims into providing access to corporate systems. This technique involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal to 'fix a connection issue', thereby granting immediate access to sensitive resources. With several variations of this attack already identified, security experts warn that most victims will not realize they have been breached until the damage has been done, and the malware has erased itself.