Lazarus Group's New Mach-O Man Attack Poses Significant Threat: CertiK

Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a direct route for stealing credentials and sensitive data. The group, responsible for an estimated $6.7 billion in cumulative losses since 2017, is specifically targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the collective's activity level has increased significantly, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks alone. Newson emphasized that the crypto industry must recognize Lazarus as a persistent and well-funded threat, rather than just a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The malware is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique has been used to compromise corporate systems, SaaS platforms, and financial resources, often without the victims' knowledge. The attack has several variations, and security researchers have reported cases where Lazarus attackers have hijacked DeFi project domains using this new malware, replacing their websites with fake messages that instruct victims to enter a command to grant access.