• bitcoinBitcoin (BTC) $ 78,906.00
  • ethereumEthereum (ETH) $ 2,400.05
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 1.44
  • bnbBNB (BNB) $ 645.79
  • usd-coinUSDC (USDC) $ 0.999757
  • solanaSolana (SOL) $ 87.61
  • tronTRON (TRX) $ 0.329047
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • dogecoinDogecoin (DOGE) $ 0.096902
  • whitebitWhiteBIT Coin (WBT) $ 56.17
  • usdsUSDS (USDS) $ 0.999698
  • hyperliquidHyperliquid (HYPE) $ 41.23
  • leo-tokenLEO Token (LEO) $ 10.23
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.253023
  • bitcoin-cashBitcoin Cash (BCH) $ 464.19
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 379.17
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 9.44
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • stellarStellar (XLM) $ 0.178713
  • canton-networkCanton (CC) $ 0.152651
  • memecoreMemeCore (M) $ 4.30
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • zcashZcash (ZEC) $ 324.16
  • daiDai (DAI) $ 0.999751
  • susdssUSDS (SUSDS) $ 1.08
  • ethena-usdeEthena USDe (USDE) $ 0.999344
  • litecoinLitecoin (LTC) $ 56.14
  • usd1-wlfiUSD1 (USD1) $ 0.999762
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • avalanche-2Avalanche (AVAX) $ 9.51
  • hedera-hashgraphHedera (HBAR) $ 0.091834
  • suiSui (SUI) $ 0.964638
  • wethWETH (WETH) $ 2,268.37
  • rainRain (RAIN) $ 0.007771
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • paypal-usdPayPal USD (PYUSD) $ 0.999848
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.38
  • crypto-com-chainCronos (CRO) $ 0.070307
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,722.03
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.079234
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bittensorBittensor (TAO) $ 247.33
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • global-dollarGlobal Dollar (USDG) $ 0.999785
  • pax-goldPAX Gold (PAXG) $ 4,727.03
  • polkadotPolkadot (DOT) $ 1.29
  • uniswapUniswap (UNI) $ 3.40
  • mantleMantle (MNT) $ 0.647881
  • skySky (SKY) $ 0.083623
  • nearNEAR Protocol (NEAR) $ 1.42
  • okbOKB (OKB) $ 85.06
  • falcon-financeFalcon USD (USDF) $ 0.997999
  • pi-networkPi Network (PI) $ 0.169242
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.684737
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pepePepe (PEPE) $ 0.000004
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • aaveAave (AAVE) $ 94.36
  • internet-computerInternet Computer (ICP) $ 2.53
  • usddUSDD (USDD) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 1.95
  • ethereum-classicEthereum Classic (ETC) $ 8.58
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • bfusdBFUSD (BFUSD) $ 1.00
  • ondo-financeOndo (ONDO) $ 0.265404
  • kucoin-sharesKuCoin (KCS) $ 8.58
  • gatechain-tokenGate (GT) $ 7.45
  • pump-funPump.fun (PUMP) $ 0.001883
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • quant-networkQuant (QNT) $ 74.32
  • morphoMorpho (MORPHO) $ 1.94
  • united-stablesUnited Stables (U) $ 1.00
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.094410
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • ethenaEthena (ENA) $ 0.110767
  • kaspaKaspa (KAS) $ 0.034705
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • cosmosCosmos Hub (ATOM) $ 1.88
  • render-tokenRender (RENDER) $ 1.83
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • algorandAlgorand (ALGO) $ 0.104024
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.922700
  • worldcoin-wldWorldcoin (WLD) $ 0.271648
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • usdtbUSDtb (USDTB) $ 0.999578
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.06
  • wbnbWrapped BNB (WBNB) $ 759.61
  • arbitrumArbitrum (ARB) $ 0.132286
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.959004
  • blockchain-capitalBlockchain Capital (BCAP) $ 82.76
  • filecoinFilecoin (FIL) $ 0.947066
  • justJUST (JST) $ 0.081892
  • flare-networksFlare (FLR) $ 0.008064
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • official-trumpOfficial Trump (TRUMP) $ 2.96
  • jupiter-exchange-solanaJupiter (JUP) $ 0.176316
  • vechainVeChain (VET) $ 0.007257
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • midnight-3Midnight (NIGHT) $ 0.037175
  • beldexBeldex (BDX) $ 0.079853
  • xdce-crowd-saleXDC Network (XDC) $ 0.030772
  • ousgOUSG (OUSG) $ 115.00
  • hash-2Provenance Blockchain (HASH) $ 0.010325
  • stable-2​​Stable (STABLE) $ 0.026851
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • yldsYLDS (YLDS) $ 0.999775
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • ghoGHO (GHO) $ 0.998876
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • bonkBonk (BONK) $ 0.000007
  • dexeDeXe (DEXE) $ 12.26
  • usual-usdUsual USD (USD0) $ 0.998290
  • clbtcclBTC (CLBTC) $ 76,920.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.008520
  • edgexedgeX (EDGE) $ 1.44
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.52
  • true-usdTrueUSD (TUSD) $ 0.998230
  • a7a5A7A5 (A7A5) $ 0.012381
  • chilizChiliz (CHZ) $ 0.046919
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.211013
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.708572
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • dashDash (DASH) $ 35.99
  • tbtctBTC (TBTC) $ 70,942.00
  • siren-2Siren (SIREN) $ 0.629498
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • adi-tokenADI (ADI) $ 4.30
  • euro-coinEURC (EURC) $ 1.17
  • blockstackStacks (STX) $ 0.230371
  • sei-networkSei (SEI) $ 0.062594
  • venice-tokenVenice Token (VVV) $ 9.16
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • tezosTezos (XTZ) $ 0.377996
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • layerzeroLayerZero (ZRO) $ 1.59
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • monadMonad (MON) $ 0.034036
  • ether-fiEther.fi (ETHFI) $ 0.467895
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • aerodrome-financeAerodrome Finance (AERO) $ 0.420399
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.376730
  • usxUSX (USX) $ 0.999468
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • spx6900SPX6900 (SPX) $ 0.396016
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • kinesis-goldKinesis Gold (KAU) $ 151.22
  • sun-tokenSun Token (SUN) $ 0.018733
  • decredDecred (DCR) $ 20.45
  • curve-dao-tokenCurve DAO (CRV) $ 0.233316
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • celestiaCelestia (TIA) $ 0.381023
  • hastra-primePRIME (PRIME) $ 1.03
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • lido-daoLido DAO (LDO) $ 0.394915
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • injective-protocolInjective (INJ) $ 3.35
  • apenftAINFT (NFT) $ 0.00000033
  • gnosisGnosis (GNO) $ 123.78
  • bitcoin-svBitcoin SV (BSV) $ 16.27
  • crvusdcrvUSD (CRVUSD) $ 0.999935
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • bittorrentBitTorrent (BTT) $ 0.00000033
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • flokiFLOKI (FLOKI) $ 0.000033
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • conflux-tokenConflux (CFX) $ 0.060808
  • doublezeroDoubleZero (2Z) $ 0.085549
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • kinesis-silverKinesis Silver (KAG) $ 77.62
  • jasmycoinJasmyCoin (JASMY) $ 0.005796
  • kaiaKaia (KAIA) $ 0.048669
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • ravedaoRaveDAO (RAVE) $ 1.14
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • usdaiUSDai (USDAI) $ 0.999558
  • pyth-networkPyth Network (PYTH) $ 0.048156
  • fraxLegacy Frax Dollar (FRAX) $ 0.993551
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • syrupMaple Finance (SYRUP) $ 0.236085
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Lazarus Group has become especially dangerous with new Mach-O Man attack: CertiK

0 3

Lazarus Group has become especially dangerous with new Mach-O Man attack: CertiK

The North Korean state-run Lazarus Group is running a new campaign known as “Mach-O Man” that turns routine business communication into a direct path to credential theft and data loss, security experts warned Wednesday.

The collective, with cumulative loot estimated at $6.7 billion since 2017, is targeting fintech, cryptocurrency and other high-value executives and firms, Natalie Newson, a senior blockchain security researcher at CertiK, told CoinDesk on Wednesday.

In the past two weeks alone, the North Korean hackers have siphoned more than $500 million from the Drift and KelpDAO exploits in what appears to be a sustained campaign. The crypto industry needs to start viewing Lazarus the same way banks view nation-state cyber actors: “as a constant and well-funded threat, not just another news headline,” she said.

“What makes Lazarus especially dangerous right now is their activity level,” Newson said. “KelpDAO, Drift, and now a new macOS malware kit, all within the same month. This isn’t random hacking; it’s a state-directed financial operation running at a scale and speed typical of institutions.”

North Korea has turned crypto theft into a lucrative national industry, and Mach-O Man is just the latest product from that process, she said. While Lazarus created it, other cybercrime groups are also using it.

“It is a modular macOS malware kit created by Lazarus Group’s infamous Chollima division. It uses native Mach-O binaries tailored for Apple environments where crypto and fintech operate,” she said.

Newson said Mach-O Man uses a delivery method known as ClickFix. “It’s important to be clear because a lot of coverage is mixing up two separate things,” she noted. ClickFix is a social engineering technique where the victim is asked to paste a command into their terminal to fix a simulated connection issue.

It works by Lazarus sending executives an “urgent” meeting invite over Telegram for a Zoom, Microsoft Teams or Google Meet call, according to Mauro Eldritch, a security expert and founder of threat intelligence firm BCA Ltd.

The link leads to a fake, but convincing, website that instructs them to copy and paste one simple command into their Mac’s terminal to “fix a connection issue.” In doing so, the victims provide immediate access to corporate systems, SaaS platforms and financial resources. By the time they find out they were exploited, it is usually too late.

There are several variations of this attack, security threat researcher Vladimir S. said on X. There are already cases where Lazarus attackers have hijacked decentralized finance (DeFI) projects’ domains with this new malware by replacing their websites with a fake message from Cloudflare, asking them to enter a command to grant access.

“These fake ‘verification steps’ guide victims through keyboard shortcuts that run a harmful command,” said Certik’s Newson. “The page looks real, the instructions seem normal, and the victim initiates the action themselves — which is why traditional security controls often miss it.”

Most victims of this hack will not realize their security has been breached until the damage has been done, at which time, the malware will have already erased itself as well.

“They likely don’t know it yet,” she said. “If they do, they probably can’t identify which variant affected them.”

Source

Leave A Reply

Your email address will not be published.