Lazarus Group's Mach-O Man Attack Poses Significant Threat to Crypto and Fintech Industries
Security experts have warned of a new campaign, dubbed 'Mach-O Man', in which the Lazarus Group is using a sophisticated social engineering technique to trick executives into granting access to corporate systems and financial resources. The group, which has amassed an estimated $6.7 billion since 2017, is targeting high-value firms in the fintech and cryptocurrency sectors. In recent weeks, the group has stolen over $500 million from exploits such as Drift and KelpDAO, demonstrating its ability to operate at a scale and speed typical of institutions. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which is tailored for Apple environments and uses a delivery method known as ClickFix. This social engineering technique involves convincing victims to paste a command into their terminal to 'fix a connection issue', thereby providing immediate access to sensitive information. The attack is particularly dangerous due to its ability to evade traditional security controls, with most victims remaining unaware of the breach until the damage has been done.