Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, dubbed 'Mach-O Man,' which enables the Lazarus Group to turn ordinary business interactions into a pathway for credential theft and data loss. The group, known for its cumulative loot of $6.7 billion since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective's activity level is particularly concerning, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks alone. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to trick victims into providing access to corporate systems. The attack involves sending executives fake meeting invites, leading them to a convincing website that instructs them to copy and paste a command into their terminal, thereby granting immediate access to sensitive resources. With its ability to erase itself after a breach, the malware often goes undetected until the damage is done.