North Korea's Lazarus Group uses macOS malware toolkit to attack cryptocurrency and fintech companies

robot
Abstract generation in progress

Odaily Planet Daily reports that according to CertiK monitoring, the Lazarus Group is conducting an attack operation called Mach-O Man targeting executives in the fintech and cryptocurrency industries. The operation uses ClickFix social engineering techniques, sending fake online meeting invitations to trick victims into pasting repair commands on their Mac terminals, thereby gaining access to company and financial systems. CertiK researcher Natalie Newson stated that over the past two weeks, Lazarus Group has stolen more than $500 million through attacks on Drift and KelpDAO. Mach-O Man is a modular macOS malware toolkit developed by Lazarus Group’s Chollima division, capable of automatically deleting itself after use to evade detection. Additionally, some attackers have carried out this attack by hijacking DeFi project domains and replacing them with fake Cloudflare messages.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin