Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a pathway for credential theft and data loss. The Lazarus Group, a state-run collective, is behind this campaign, targeting high-value executives and firms in the fintech and cryptocurrency sectors. With estimated cumulative loot of $6.7 billion since 2017, the group has siphoned over $500 million in the past two weeks alone from the Drift and KelpDAO exploits. According to Natalie Newson, a senior blockchain security researcher at CertiK, what makes Lazarus particularly dangerous is their high activity level, with multiple exploits, including a new macOS malware kit, all within the same month. This suggests a state-directed financial operation rather than random hacking. The Mach-O Man campaign utilizes a modular macOS malware kit created by Lazarus Group's Chollima division, tailored for Apple environments where crypto and fintech operate. The delivery method, known as ClickFix, involves social engineering, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. This allows immediate access to corporate systems, SaaS platforms, and financial resources. Variations of this attack exist, with cases of Lazarus attackers hijacking DeFI projects' domains using this new malware. The fake 'verification steps' guide victims through keyboard shortcuts that run a harmful command, often evading traditional security controls. Most victims remain unaware of the security breach until the damage is done, and the malware has erased itself.