Lazarus Group Poses Enhanced Threat with Mach-O Man Attack: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man,' where the Lazarus Group exploits business communications to steal credentials and compromise data. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, targets high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective has siphoned over $500 million in the past two weeks alone from the Drift and KelpDAO exploits. Newson emphasizes that the crypto industry should view Lazarus as a constant and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix. This technique involves convincing victims to paste a command into their terminal to resolve a simulated connection issue, providing immediate access to corporate systems and financial resources. The attack often goes undetected until the damage is done, and the malware has self-erased. Variations of this attack have already been reported, with cases of Lazarus attackers hijacking DeFi project domains and replacing their websites with fake messages. CertiK's Newson notes that traditional security controls often miss these attacks due to their sophisticated nature, making it essential for the industry to be vigilant and proactive in countering the Lazarus Group's threats.