Lazarus Group Intensifies Threat with Mach-O Man Attack: CertiK

Security experts have warned of a new campaign, known as 'Mach-O Man', which enables the Lazarus Group to turn routine business communications into a direct path for credential theft and data loss. The group, responsible for an estimated $6.7 billion in cumulative loot since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level is particularly concerning, with over $500 million siphoned from recent exploits. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which uses native Mach-O binaries tailored for Apple environments. The malware is delivered through a social engineering technique known as ClickFix, where victims are tricked into pasting a command into their terminal to 'fix a connection issue'. This technique has already been used to hijack DeFI project domains, with fake messages from Cloudflare asking victims to enter a command to grant access. The malware is highly evasive, erasing itself after a breach, making it difficult for victims to realize they have been compromised.