North Korea has transformed cryptocurrency theft into a highly profitable national endeavor, and the latest development in this strategy is a malware called Mach-O Man, according to experts. While this tool was developed by the Lazarus Group, it’s also being utilized by various other cybercriminal organizations.

“Mach-O Man is a modular malware kit designed for macOS, created by the notorious Chollima division of the Lazarus Group. It utilizes Mach-O binaries specifically crafted for Apple systems where cryptocurrency and financial technology operate,” she explained.

Newson highlighted that Mach-O Man is distributed using a technique referred to as ClickFix. “It’s critical to clarify this, as many reports are conflating two different aspects,” she pointed out. ClickFix involves a social engineering tactic where victims are prompted to enter a command into their terminal to address a fabricated connectivity problem.

The scheme involves Lazarus sending executives an “urgent” meeting request via Telegram for a virtual call on platforms like Zoom, Microsoft Teams, or Google Meet, as detailed by Mauro Eldritch, an expert in cybersecurity and founder of the threat intelligence company BCA Ltd.

The provided link directs victims to a seemingly legitimate website that urges them to copy and paste a simple command into their Mac’s terminal to resolve a “connection issue.” By doing so, they inadvertently grant access to their company’s systems, software platforms, and financial accounts. Often, by the time they realize they have been compromised, it is already too late.

Share.