Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business interactions into a conduit for credential theft and data breaches. The Lazarus Group, a state-sponsored collective, has been targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has stolen over $500 million from the Drift and KelpDAO exploits, underscoring the need for the crypto industry to regard Lazarus as a persistent and well-funded threat. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to deceive victims into providing access to corporate systems and financial resources. The attack involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal, thereby granting immediate access to sensitive information. Variations of this attack have already been identified, with some cases involving the hijacking of DeFi project domains and the use of fake Cloudflare messages to trick victims into executing harmful commands. The malware often erases itself after a breach, making it difficult for victims to detect and identify the specific variant used.