Lazarus Group Elevates Threat Level with Mach-O Man Attack

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a direct route for credential theft and data loss. The Lazarus Group, a state-run collective with estimated cumulative loot of $6.7 billion since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group has stolen over $500 million in the past two weeks alone from the Drift and KelpDAO exploits. Newson emphasized that the crypto industry should view Lazarus as a constant and well-funded threat, rather than just a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The malware kit is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. The attack begins with an 'urgent' meeting invite sent to executives over Telegram, leading to a fake website that instructs them to copy and paste a command into their Mac's terminal. By doing so, victims provide immediate access to corporate systems, SaaS platforms, and financial resources. The malware is designed to erase itself after the damage is done, making it challenging for victims to realize they have been breached. Variations of this attack have already been reported, with cases of Lazarus attackers hijacking DeFI projects' domains and replacing their websites with fake messages from Cloudflare.