Lazarus Group's Mach-O Man Attack Poses Significant Threat to Crypto and Fintech

Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a direct route for credential theft and data loss. The Lazarus Group, a state-run collective, is targeting high-value executives and firms in the fintech and cryptocurrency sectors, with estimated cumulative loot of $6.7 billion since 2017. In recent weeks, the group has stolen over $500 million from exploits such as Drift and KelpDAO, demonstrating a sustained and well-funded campaign. The Mach-O Man attack utilizes a modular macOS malware kit, created by Lazarus' Chollima division, which employs a social engineering technique known as ClickFix to trick victims into providing access to corporate systems. The attack involves sending 'urgent' meeting invites over Telegram, leading to a fake website that instructs victims to copy and paste a command into their Mac's terminal, thereby granting immediate access to sensitive resources. Variations of this attack have already been reported, with some cases involving the hijacking of DeFi project domains and the use of fake Cloudflare messages to trick victims into initiating harmful commands. The attack often goes undetected until the damage is done, at which point the malware erases itself, leaving victims unaware of the breach.