Lazarus Group's Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency

Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to transform ordinary business communications into a direct pathway for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is primarily targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has successfully siphoned over $500 million from exploits such as Drift and KelpDAO, highlighting the need for the crypto industry to view Lazarus as a persistent and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to deceive victims into providing access to corporate systems and financial resources. By the time the victims realize they have been exploited, it is often too late, and the malware has already self-erased, leaving minimal evidence of the breach.