Svmuu News: According to CertiK’s monitoring, the Lazarus Group is conducting a campaign called “Mach-O Man” targeting executives in the fintech and cryptocurrency industries. The operation leverages ClickFix social engineering techniques, sending fake online meeting invitations to trick victims into pasting repair commands into their Mac terminals, thereby gaining access to corporate and financial systems. CertiK researcher Natalie Newson stated that the Lazarus Group has stolen over $500 million through attacks on Drift and KelpDAO over the past two weeks. Mach-O Man is a modular macOS malware toolkit developed by the Lazarus Group’s Chollima unit, designed to self-delete after use to evade detection. Additionally, attackers have carried out this campaign by hijacking DeFi project domains and replacing them with fake Cloudflare messages.