Lazarus Group's Mach-O Man Attack: A New Threat to Business Security

Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to turn ordinary business interactions into a direct route to credential theft and data loss. The group, estimated to have amassed $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has successfully siphoned over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. The Mach-O Man malware kit, created by Lazarus' Chollima division, uses native Mach-O binaries tailored for Apple environments and employs a social engineering technique known as ClickFix to deliver the malware. This technique involves tricking victims into pasting a command into their terminal to 'fix a connection issue', thereby granting immediate access to corporate systems and financial resources. The attack is particularly dangerous due to its ability to evade traditional security controls and erase itself after the damage has been done, leaving most victims unaware of the breach until it's too late.