Lazarus Group's Latest Mach-O Man Attack Poses Significant Threat: CertiK
Security researchers at CertiK have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to exploit standard business communication, leading to credential theft and data loss. The group, known for its state-sponsored cyber activities, has been targeting high-value executives and firms in the fintech and cryptocurrency sectors. With estimated cumulative loot of $6.7 billion since 2017, the collective has recently siphoned over $500 million from the Drift and KelpDAO exploits. The Mach-O Man campaign involves a modular macOS malware kit, created by Lazarus Group's Chollima division, which uses native Mach-O binaries tailored for Apple environments. The malware is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to 'fix a connection issue'. This grants immediate access to corporate systems, SaaS platforms, and financial resources. The attack is particularly dangerous due to its ability to evade traditional security controls, with most victims unaware of the breach until the damage is done.