#BlueNoroff
excited bc today @huntress.com is releasing our analysis of a gnarly intrusion into a web3 company by the DPRK's BlueNoroff!! 🤠

we've observed 8 new pieces of macOS malware from implants to infostealers! and they're actually good (for once)!

www.huntress.com/blog/inside-...
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
www.huntress.com
June 18, 2025 at 8:53 PM
North Koreans reportedly host fake Zoom meeting featuring multiple deepfake colleagues. Target’s microphone doesn’t work so the colleagues talk them through installing malicious fix. www.huntress.com/blog/inside-...
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
www.huntress.com
June 19, 2025 at 10:41 AM
🔥 New from Phil Stokes, Raffaele Sabato and Me:

🇰🇵 BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence

www.sentinelone.com/labs/bluenor...
BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence
SentinelLabs has observed a suspected DPRK threat actor targeting Crypto-related businesses with novel multi-stage malware.
www.sentinelone.com
November 7, 2024 at 3:52 PM
Been busy this week digging in to a BlueNoroff attack.
Mac's don't get viruses, right? 🍏

Deepfake Zoom calls. AppleScript lures. Rosetta 2 abuse.

Plenty of custom malware: Nim backdoor, Go infostealer, Obj-C keylogger, and more!

Amazing write-up by @re.wtf , @stuartjash.bsky.social and Jonathan Semon 🔥

🔗 www.huntress.com/blog/inside-...
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
www.huntress.com
June 18, 2025 at 9:52 PM
If I hear one more person referring to Bluenoroff as Lazarus Group ISTG 🙃🙃🙃🙃🙃
(Or WORSE, calling Contagious Interview “Lazarus”. Or Kimsuky “Lazarus”. Or IT Workers “Lazarus”. I will literally SCREAM 🫠)
March 19, 2026 at 5:10 PM
"Inside the BlueNoroff Web3 macOS Intrusion Analysis" published by Huntress. #BlueNoroff, #macOS, #DPRK, #CTI https://www.huntress.com/blog/inside-bluenoroff-web3-intrusion-analysis
June 18, 2025 at 11:30 PM
Last week, we released new research about new Mac #malware with TTPs consistent with suspected DPRK #APT BlueNoroff. s1.ai/BNThief. This week, friends-of-NK say we’re shills for US gov. 😂 easternherald.com/2024/11/10/s...
Hate to break it to ‘em, but that ain’t how we roll. 😆
BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence
SentinelLabs has observed a suspected DPRK threat actor targeting Crypto-related businesses with novel multi-stage malware.
s1.ai
November 12, 2024 at 2:39 PM
However, to show how mad it is right now, let's look at ATP 38 aka NICKEL GLADSTONE aka BeagleBoyz aka Bluenoroff aka Stardust Chollima aka Sapphire Sleet aka COPERNICIUM aka BLOODY NORTH KOREANS DOING CRIME
January 3, 2025 at 9:41 AM
Based on screenshots and videos of past meetings found in a BlueNoroff server, more than 100 Web3 devs fell for it and hopped on meetings
Arctic Wolf Labs reports BlueNoroff using fintech-themed impersonation & fake Zoom meetings to target a N. American Web3 company. The victim’s live camera feed was captured for reuse in future lures; the infection chain deployed fileless PowerShell & browser injection. arcticwolf.com/resources/bl...
April 28, 2026 at 1:44 PM
#NorthKorean threat actor #BlueNoroff has been targeting crypto-related businesses with a new multi-stage malware for macOS systems. #malware #cyberattacks www.bleepingcomputer.com/news/securit...
North Korean hackers use new macOS malware against crypto firms
North Korean threat actor BlueNoroff has been targeting crypto-related businesses with a new multi-stage malware for macOS systems.
www.bleepingcomputer.com
November 8, 2024 at 9:35 PM
DPRK-linked BlueNoroff used macOS malware with novel persistence
BlueNoroff used macOS malware with novel persistence
SentinelLabs observed North Korea-linked threat actor BlueNoroff targeting businesses in the crypto industry with a new multi-stage malware.
securityaffairs.com
November 7, 2024 at 5:27 PM
North Korean hackers BlueNoroff blamed for cyber attack on Canadian gambling firm readwrite.com/bluenoroff-t...
North Korean hackers BlueNoroff blamed for cyber attack on Canadian gambling firm
BlueNoroff, the North Korean hackers, is utilizing deepfakes and fake Zoom calls to steal crypto, with a Canadian gambling firm targeted
readwrite.com
June 28, 2025 at 11:18 AM
North Korean advanced persistent threat (APT) 'BlueNoroff' (aka 'Sapphire Sleet' or 'TA444') are using deepfake company executives during fake Zoom calls to trick employees into installing custom malware on their computers.
North Korean hackers deepfake execs in Zoom call to spread Mac malware
North Korean advanced persistent threat (APT) 'BlueNoroff' (aka 'Sapphire Sleet' or 'TA444') are using deepfake company executives during fake Zoom calls to trick employees into installing custom malware on their computers.
www.bleepingcomputer.com
June 18, 2025 at 8:38 PM
Crypto-powered gift card store Bitrefill says that the attack it suffered at the beginning of the month was likely perpetrated by North Korean hackers of the Bluenoroff group.
Bitrefill blames North Korean Lazarus group for cyberattack
Crypto-powered gift card store Bitrefill says that the attack it suffered at the beginning of the month was likely perpetrated by North Korean hackers of the Bluenoroff group.
www.bleepingcomputer.com
March 19, 2026 at 5:08 PM
Mac's don't get viruses, right? 🍏

Deepfake Zoom calls. AppleScript lures. Rosetta 2 abuse.

Plenty of custom malware: Nim backdoor, Go infostealer, Obj-C keylogger, and more!

Amazing write-up by @re.wtf , @stuartjash.bsky.social and Jonathan Semon 🔥

🔗 www.huntress.com/blog/inside-...
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
www.huntress.com
June 18, 2025 at 9:13 PM
Hot on the heels of the researched published by @huntress.com, hunting for Zoom-themed lures from DPRK's #BlueNoroff

💥Learn hunting techniques
💥Leverage new Validin features and data
💥Full, unredacted indicator list (domains, IPs, hashes)

www.validin.com/blog/zooming...
Zooming through BlueNoroff Indicators with Validin | Validin
Pivoting through recently-reported indicators to find BlueNoroff-associated domains
www.validin.com
June 20, 2025 at 5:24 PM
Blockchain investigator ZachXBT has published a report on how the APT38 (Bluenoroff) group laundered $200 million worth of crypto from 25+ hacks to fiat between 2020 and 2023.

paragraph.com/@investigati...
How Lazarus Group laundered $200M from 25+ crypto hacks to fiat from 2020–2023
Table of contents1). Introduction 2). CoinBerry, Unibright, & CoinMetro hacks 3). Nexus Mutual founder hack 4). EasyFi hack 5). Bondly hack 6). Unreported hacks 7). MGNR and PolyPlay hacks 8). bZx hac...
paragraph.com
November 20, 2025 at 1:34 PM
--Supply chain attack compromised Trivy vulnerability scanner,
--UK Financial Conduct Authority gave Palantir access to sensitive data,
--Hackers stole $23m in Ether from DeFi protocol Resolv Labs,
--Bluenoroff group stole 18.5k purchase records from gift card platform Bitrefill, 2/5
March 23, 2026 at 1:34 PM
#100DaysofYARA - Day 9
YARA looks for the header used in a .SCPT file used by BlueNoroff (DPRK) to target MacOS systems.

Script is delivered to victims disguised as a Zoom meeting launcher.
e.g. a7c7d75c33aa809c231f1b22521ae680248986c980b45aa0881e19c19b7b1892

Rule at end
1/3
January 10, 2026 at 7:17 PM
🚨 ALERT: BlueNoroff, linked to North Korea's #Lazarus Group, launches macOS #malware called ObjCShellz. Learn about its use in RustBucket and how to protect your systems.
thehackernews.com/2023/11/n-ko...
#cybersecurity #informationsecurity
N. Korea's BlueNoroff Blamed for Hacking macOS Machines with ObjCShellz Malware
BlueNoroff, linked to North Korea's Lazarus Group, is behind a new macOS malware called ObjCShellz.
thehackernews.com
November 8, 2023 at 9:22 PM
Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff.
Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff.
www.bleepingcomputer.com
June 20, 2026 at 2:12 PM
"Zoom & doom: BlueNoroff call opens the door" published by FieldEffect. #BlueNoroff, #DPRK, #CTI https://fieldeffect.com/blog/zoom-doom-bluenoroff-call-opens-the-door
June 22, 2025 at 11:30 PM