Lazarus Group's Latest 'Mach-O Man' Attack Poses Significant Threat to Crypto and Fintech Firms
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a direct pathway for credential theft and data loss. The Lazarus Group, a state-run collective with estimated cumulative loot of $6.7 billion since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the group has successfully siphoned over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained campaign. The crypto industry is advised to regard Lazarus as a constant and well-funded threat, rather than merely another news headline. The group's activity level, including the recent deployment of a new macOS malware kit, underscores the scale and speed of their state-directed financial operations. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs native Mach-O binaries tailored for Apple environments. The delivery method, known as ClickFix, involves social engineering tactics where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique has been used to target executives with 'urgent' meeting invites, leading to fake websites that instruct victims to grant access to corporate systems and financial resources. The attack has several variations, including hijacking DeFI project domains and replacing websites with fake messages from Cloudflare. Traditional security controls often fail to detect these threats, as the malware erases itself after the damage has been done, leaving victims unaware of the breach.