Lazarus Group's Mach-O Man Attack Poses Significant Threat to Crypto and Fintech
Security experts have warned of a new campaign, known as 'Mach-O Man', which transforms standard business interactions into a direct conduit for credential theft and data loss. The Lazarus Group, a state-run collective with estimated cumulative loot of $6.7 billion since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has stolen over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained campaign. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just a news headline. The group's activity level, including the KelpDAO, Drift, and a new macOS malware kit, all within the same month, is indicative of a state-directed financial operation. North Korea has established crypto theft as a lucrative national industry, with Mach-O Man being the latest product. While created by Lazarus, other cybercrime groups are also utilizing this malware kit. It is a modular macOS malware kit, tailored for Apple environments where crypto and fintech operate, and uses a delivery method known as ClickFix. This social engineering technique involves the victim being asked to paste a command into their terminal to fix a simulated connection issue. The attack works by sending executives an 'urgent' meeting invite over Telegram, leading to a fake website that instructs them to copy and paste a command into their Mac's terminal, providing immediate access to corporate systems, SaaS platforms, and financial resources. By the time the victims discover they have been exploited, it is often too late. There are several variations of this attack, and cases have been reported where Lazarus attackers have hijacked DeFI projects' domains with this new malware. The fake 'verification steps' guide victims through keyboard shortcuts that run a harmful command, often going undetected by traditional security controls. Most victims will not realize their security has been breached until the damage has been done, at which point the malware will have already erased itself.