Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK
Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective's activity level is a cause for concern, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks alone. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to deliver the malware. This technique involves sending executives fake meeting invites, leading them to a convincing website that instructs them to copy and paste a command into their Mac's terminal, thereby granting immediate access to corporate systems and financial resources. The attack is particularly dangerous due to its ability to evade traditional security controls, with most victims unlikely to realize their security has been breached until the damage has been done.