Lazarus Group Intensifies Threat with New Mach-O Man Attack
Security experts have warned of a new campaign by the Lazarus Group, known as 'Mach-O Man', which transforms ordinary business interactions into a gateway for credential theft and data loss. The campaign, targeting high-value executives and firms in the fintech and cryptocurrency sectors, has already resulted in the theft of over $500 million in the past two weeks. According to Natalie Newson, a senior blockchain security researcher at CertiK, the Lazarus Group's activity level is particularly alarming, with multiple high-profile exploits occurring within a short timeframe. The group's Mach-O Man malware kit, created by its infamous Chollima division, uses a social engineering technique called ClickFix to trick victims into granting access to their systems. The attack involves sending fake meeting invites over Telegram, leading to a convincing website that instructs victims to copy and paste a command into their Mac's terminal to 'fix a connection issue'. This provides immediate access to corporate systems, SaaS platforms, and financial resources. The malware is highly evasive, erasing itself after the damage is done, making it challenging for victims to detect and identify the breach.