Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK Warning

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communication into a conduit for credential theft and data loss. The Lazarus Group, known for its cumulative loot of $6.7 billion since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In the past two weeks, the group has siphoned over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained campaign. According to Natalie Newson, a senior blockchain security researcher at CertiK, the crypto industry must view Lazarus as a constant and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix. This technique involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal, thereby granting access to corporate systems and financial resources. The attack is often undetectable until the damage is done, and the malware erases itself, making it challenging for victims to identify the variant that affected them.