Lazarus Group's New 'Mach-O Man' Attack Puts Fintech and Crypto Executives at Risk: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', where the Lazarus Group is utilizing a modular macOS malware kit to target high-value executives and firms in the fintech and cryptocurrency sectors. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, has been particularly active in recent weeks, with over $500 million siphoned from the Drift and KelpDAO exploits. According to Natalie Newson, a senior blockchain security researcher at CertiK, the crypto industry must view Lazarus as a constant and well-funded threat. The Mach-O Man campaign uses a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to 'fix a connection issue', providing immediate access to corporate systems and financial resources. The attack is nearly undetectable, with most victims unaware of the breach until the damage is done, and the malware has erased itself.