Lazarus Group's Mach-O Man Attack Elevates Threat Level: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which enables the Lazarus Group to transform ordinary business interactions into a conduit for credential theft and data loss. The group, estimated to have amassed $6.7 billion since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. In recent weeks, the hackers have stolen over $500 million from the Drift and KelpDAO exploits, demonstrating a sustained and well-funded campaign. The 'Mach-O Man' attack utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs native Mach-O binaries tailored for Apple environments. The delivery method, known as ClickFix, involves social engineering tactics where victims are tricked into pasting a command into their terminal to resolve a simulated connection issue. This technique allows the hackers to gain immediate access to corporate systems, SaaS platforms, and financial resources, often going undetected until the damage is done.