Lazarus Group's Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency Firms
Security experts have warned of a new campaign by the North Korean state-run Lazarus Group, which has been dubbed 'Mach-O Man'. This campaign involves the use of a modular macOS malware kit to target high-value executives and firms in the fintech and cryptocurrency sectors. The kit, created by Lazarus Group's Chollima division, uses native Mach-O binaries tailored for Apple environments and is delivered through a social engineering technique known as ClickFix. This technique involves sending executives an 'urgent' meeting invite over Telegram, which leads to a fake website that instructs them to copy and paste a command into their Mac's terminal to 'fix a connection issue'. By doing so, the victims provide immediate access to corporate systems, SaaS platforms, and financial resources. The attack has already resulted in the theft of over $500 million in the past two weeks alone, and security experts are warning that the crypto industry needs to take a more proactive approach to addressing the threat posed by Lazarus Group. The group's activity level has increased significantly in recent months, with multiple high-profile exploits, including the Drift and KelpDAO hacks. The use of Mach-O Man is just the latest example of North Korea's efforts to turn crypto theft into a lucrative national industry.