Lazarus Group's New Mach-O Man Attack Poses Significant Threat to Fintech and Cryptocurrency Firms

Security experts have warned of a new campaign, known as 'Mach-O Man,' which enables the Lazarus Group to transform routine business communication into a direct pathway for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the North Korean hackers have successfully siphoned over $500 million from the Drift and KelpDAO exploits, highlighting the sustained nature of their campaign. According to Natalie Newson, a senior blockchain security researcher at CertiK, the crypto industry must view Lazarus as a constant and well-funded threat, rather than just another news headline. The group's activity level, including the recent KelpDAO, Drift, and macOS malware kit exploits, demonstrates a state-directed financial operation running at an institutional scale and speed. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs native Mach-O binaries tailored for Apple environments. The malware is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to fix a simulated connection issue. This technique has been used to hijack decentralized finance (DeFI) projects' domains, replacing their websites with fake messages that instruct victims to enter a command to grant access. The attack often goes undetected until the damage has been done, at which point the malware has already erased itself, leaving victims unaware of the breach.