#GhostCall
Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains
Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains
thehackernews.com
October 28, 2025 at 5:23 PM
🚨 BlueNoroff’s GhostCall & GhostHire campaigns target Web3 & VC professionals.
🎭 Fake video calls + GitHub job lures → malware & data theft.
💻 macOS + Windows infostealers active.

#CyberSecurity #BlueNoroff #GhostCall #GhostHire #APT
October 28, 2025 at 5:13 PM
Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
October 29, 2025 at 1:11 PM
BlueNoroff Expands Potatoattacks with AI-Driven Campaigns Targeting Executives BlueNoroff uses AI-driven attacks in GhostCall and GhostHire to target global crypto and tech executives. The post Blue...

#Potatosecurity #News #Threats

Origin | Interest | Match
October 29, 2025 at 4:41 PM
North Korean hackers (BlueNoroff) are deploying "GhostCall" (fake Zoom/Teams updates) & "GhostHire" (Web3 job ads on Telegram) to spread malware. SilentSiphon steals data from Apple Notes, Telegram, browsers & cloud accounts (AWS, Google, OpenAI, Solana).

#crypto #blockchain #news
October 29, 2025 at 12:44 AM
GhostCall & GhostHire — two ongoing campaigns tied to North Korea’s Lazarus sub-cluster BlueNoroff, part of the long-running SnatchCrypto operation. They target Web3 and blockchain professionals via Telegram lures posing as investors or recruiters.
#CyberEspionage #APT38 #Web3Threats
October 30, 2025 at 11:26 AM
According to Kaspersky, the campaigns are part of a broader operation called SnatchCrypto that has been underway since at least 2017. thehackernews.com/2025/10/rese...
Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains
BlueNoroff’s GhostCall and GhostHire campaigns target Web3 firms using fake Zoom calls and Telegram job lures
thehackernews.com
October 29, 2025 at 12:27 PM
GhostCall y GhostHire: BlueNoroff ataca cripto y Web3 con ingeniería social y malware avanzado - Una Al Día
GhostCall y GhostHire: BlueNoroff ataca cripto y Web3 con ingeniería social y malware avanzado - Una Al Día
hispasec.us16.list-manage.com
November 19, 2025 at 3:16 PM
BlueNoroff Expands Cyberattacks with AI-Driven Campaigns Targeting Executives BlueNoroff uses AI-driven attacks in GhostCall and GhostHire to target global crypto and tech executives. The post Blue...

#Cybersecurity #News #Threats

Origin | Interest | Match
BlueNoroff Expands Cyberattacks with AI-Driven Campaigns Targeting Executives | eSecurity Planet
BlueNoroff uses AI-driven attacks in GhostCall and GhostHire to target global crypto and tech executives.
www.esecurityplanet.com
October 29, 2025 at 4:26 PM
Кіберзлочинці, пов’язані з Північною Кореєю, активно атакують сектори Web3 та блокчейн у рамках двох кампаній під назвами GhostCall та GhostHire. Ці операції є частиною більш масштабної кампанії SnatchCrypto, яка спрямована на крадіжку криптовалют.
Дослідники виявили GhostCall та GhostHire: нові ланцюги шкідливого ПЗ BlueNoroff | CyberCalm
Дослідники Kaspersky виявили нові кампанії GhostCall та GhostHire групи BlueNoroff, які атакують Web3 та блокчейн-сектори для крадіжки криптовалют
cybercalm.org
October 31, 2025 at 1:22 PM
BlueNoroff reemerges with new campaigns for crypto theft and espionage
North Korea-aligned threat actor BlueNoroff, also known under aliases APT38 and TA444, has resurfaced with two new campaigns dubbed “GhostCall” and “GhostHire,” targeting executives, Web3 developers, and blockchain professionals. According to Kaspersky’s Securelist researchers, the campaigns rely on social engineering via platforms like Telegram and LinkedIn to send fake meeting invites and eventually deliver multi-stage malware chains to compromise macOS and Windows hosts. BlueNoroff is a financially motivated subgroup of the Lazarus Group, North Korea’s state-sponsored cyber unit linked to the Reconnaissance General Bureau (RGB), and is believed to operate the long-running SnatchCrypto campaign, of which GhostCall and GhostHire appear to be the latest extensions. Researchers noted that the new campaigns highlight BlueNoroff’s shift toward modular malware, cross-platform threats, and highly tailored targeting of the blockchain space. The malware samples were found written in multiple programming languages, including Go, Rust, Nim, and AppleScript, reflecting an added technical layer in the group’s operations. ## Compromise through fake “investor meetings” In the GhostCall campaign, BlueNoroff poses as venture capitalists or startup founders seeking to “invest” in blockchain projects. The attackers set up fake video meetings via platforms like Zoom or Teams, luring victims into a false sense of legitimacy. During or after these calls, the victim is asked to install a supposed “update” or “plugin” to improve connection quality. The file, of course, is malicious–triggering a chain of implants such as DownTroy, CosmicDoor, and Rootroy, each performing specialized tasks like credential theft, keylogging, or persistence. Once inside the target environment, the malware seeks out crypto wallet data, SSH keys, and project credentials–anything that could enable financial theft or lateral movement within corporate infrastructure. The campaign also deploys exfiltration routines to extract sensitive project data back to BlueNoroff’s servers, often obfuscated with custom encryption and encoded in hexadecimal to avoid detection. Securelist researchers emphasized that GhostCall marks a major leap in operational stealth compared to earlier BlueNoroff operations. The attackers use multiple layers of staging and dynamic command-and-control switching, allowing the malware to remain dormant until it detects activity in crypto-related directories or developer tools. ## Fake recruiters with real malware The GhostHire operation takes a different approach, targeting Web3 developers through fake job offers and recruitment tests. Here BlueNoroff sets up fake developer tasks, often hosted on GitHub or shared via Telegram bots. “Based on historical attack cases of this campaign, we assess with medium confidence that this attack flow involving Telegram and GitHub represents the latest phase, which started no later than April this year,” researchers said. Victims are told to complete a “coding challenge” for a potential employer, only to receive a ZIP archive or Git repository containing the malware. Once executed, GhostHire deploys system reconnaissance modules that determine the victim’s OS–macOS or Windows–and then selectively downloads the right payload. These payloads share the same modular DNA as GhostCall’s tools, designed to escalate privileges, capture credentials, and open backdoors. Researchers noted that the social engineering component is particularly convincing, with attackers sometimes maintaining week-long correspondence to earn the victim’s trust before deploying the payload. Recently, BlueNoroff and its parent, Lazarus Group, have expanded their operations with the $1.5 billion Bybit heist, npm-supply-chain attacks, and Mac-focused malware targeting blockchain developers.
www.csoonline.com
October 29, 2025 at 4:06 PM
BlueNoroff reemerges with new campaigns for crypto theft and espionage
North Korea-aligned threat actor BlueNoroff, also known under aliases APT38 and TA444, has resurfaced with two new campaigns dubbed “GhostCall” and “GhostHire,” targeting executives, Web3 developers, and blockchain professionals. According to Kaspersky’s Securelist researchers, the campaigns rely on social engineering via platforms like Telegram and LinkedIn to send fake meeting invites and eventually deliver multi-stage malware chains to compromise macOS and Windows hosts. BlueNoroff is a financially motivated subgroup of the Lazarus Group, North Korea’s state-sponsored cyber unit linked to the Reconnaissance General Bureau (RGB), and is believed to operate the long-running SnatchCrypto campaign, of which GhostCall and GhostHire appear to be the latest extensions. Researchers noted that the new campaigns highlight BlueNoroff’s shift toward modular malware, cross-platform threats, and highly tailored targeting of the blockchain space. The malware samples were found written in multiple programming languages, including Go, Rust, Nim, and AppleScript, reflecting an added technical layer in the group’s operations. ## Compromise through fake “investor meetings” In the GhostCall campaign, BlueNoroff poses as venture capitalists or startup founders seeking to “invest” in blockchain projects. The attackers set up fake video meetings via platforms like Zoom or Teams, luring victims into a false sense of legitimacy. During or after these calls, the victim is asked to install a supposed “update” or “plugin” to improve connection quality. The file, of course, is malicious–triggering a chain of implants such as DownTroy, CosmicDoor, and Rootroy, each performing specialized tasks like credential theft, keylogging, or persistence. Once inside the target environment, the malware seeks out crypto wallet data, SSH keys, and project credentials–anything that could enable financial theft or lateral movement within corporate infrastructure. The campaign also deploys exfiltration routines to extract sensitive project data back to BlueNoroff’s servers, often obfuscated with custom encryption and encoded in hexadecimal to avoid detection. Securelist researchers emphasized that GhostCall marks a major leap in operational stealth compared to earlier BlueNoroff operations. The attackers use multiple layers of staging and dynamic command-and-control switching, allowing the malware to remain dormant until it detects activity in crypto-related directories or developer tools. ## Fake recruiters with real malware The GhostHire operation takes a different approach, targeting Web3 developers through fake job offers and recruitment tests. Here BlueNoroff sets up fake developer tasks, often hosted on GitHub or shared via Telegram bots. “Based on historical attack cases of this campaign, we assess with medium confidence that this attack flow involving Telegram and GitHub represents the latest phase, which started no later than April this year,” researchers said. Victims are told to complete a “coding challenge” for a potential employer, only to receive a ZIP archive or Git repository containing the malware. Once executed, GhostHire deploys system reconnaissance modules that determine the victim’s OS–macOS or Windows–and then selectively downloads the right payload. These payloads share the same modular DNA as GhostCall’s tools, designed to escalate privileges, capture credentials, and open backdoors. Researchers noted that the social engineering component is particularly convincing, with attackers sometimes maintaining week-long correspondence to earn the victim’s trust before deploying the payload. Recently, BlueNoroff and its parent, Lazarus Group, have expanded their operations with the $1.5 billion Bybit heist, npm-supply-chain attacks, and Mac-focused malware targeting blockchain developers.
www.csoonline.com
October 29, 2025 at 1:27 PM
Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains

Threat actors tied to North Korea have been observed targeting the Web3 and blockchain sectors as part of twin campaigns tracked as GhostCall and GhostHire.
According to Kaspersky, the campaigns are part …
#hackernews #news
Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains
Threat actors tied to North Korea have been observed targeting the Web3 and blockchain sectors as part of twin campaigns tracked as GhostCall and GhostHire. According to Kaspersky, the campaigns are part of a broader operation called SnatchCrypto that has been underway since at least 2017. The activity is attributed to a Lazarus Group sub-cluster called BlueNoroff, which is also known as APT38,
thehackernews.com
October 29, 2025 at 3:52 PM
🟢 BlueNoroff Uses AI in Attacks on Blockchain Project Executives

🗨️ Researchers at Kaspersky Lab reported new targeted attacks by the BlueNoroff group. The malicious GhostCall and GhostHir…

#news
BlueNoroff Uses AI in Attacks on Blockchain Project Executives
Read more
hackmag.com
March 25, 2026 at 9:40 AM
GhostCallとGhostHire:暗号資産の狩猟

Kaspersky Global Research and Analysis Team(GReAT)のエキスパートが、Security Analyst Summit 2025において、LazarusのサブグループとみられるBlueNoroff APTグループの活動について講演しました。特に、暗号資産業界の開発者や経営幹部を標的とした2つのキャンペーン、「GhostCall」と「GhostHire」について詳細に説明しました。

BlueNoroffの攻撃者は主に金銭的利益を目的としており、現在はブロックチェーンを取り扱う組織の従業...
GhostCall and GhostHire — two campaigns by BlueNoroff
GhostCall and GhostHire, two campaigns by the BlueNoroff APT group (a subgroup of Lazarus), target developers and executives in the crypto industry.
www.kaspersky.com
November 26, 2025 at 12:47 PM
BlueNoroffが戦術を転換:新たな侵入手法で経営幹部や管理職をターゲットに

北朝鮮とつながりのある脅威グループ BlueNoroff (別名 Sapphire Sleet、APT38、Alluring Pisces) は、金銭的利益を主な目的としながら、攻撃戦術を進化させ続けています。

同グループは戦略を転換し、Web3およびベンチャーキャピタル分野のCレベルの経営幹部、管理職、ブロックチェーン開発者など、価値の高い被害者をターゲットにした、洗練された新しい侵入方法を採用している。

セキュリティ研究者は、GhostCallとGhostHireと呼ばれる2つの異なるキャンペーン...
BlueNoroff Shifts Tactics: Targets C-Suite and Managers with New Infiltration Methods
The North Korean-linked threat group BlueNoroff, also known by aliases including Sapphire Sleet, APT38, and Alluring Pisces, continues to evolve its attack tactics.
gbhackers.com
November 26, 2025 at 12:42 PM
暗号通貨の無駄遣い:ブルーノロフの資金調達と雇用の幻影

BlueNoroff(別名:Sapphire Sleet、APT38、Alluring Pisces、Stardust Chollima、TA444)は、登場以来、主に金銭的利益を目的としており、時間の経過とともに新たな侵入戦略とマルウェアセットを採用してきましたが、SnatchCryptoオペレーションの一環として、依然としてブロックチェーン開発者、経営幹部、Web3/ブロックチェーン業界の管理職を標的としています。今年初め、私たちはBlueNoroffによるSnatchCryptoオペレーションに基づく2つの悪意のあるキャン...
BlueNoroff's latest campaigns: GhostCall and GhostHire
Kaspersky GReAT experts dive deep into the BlueNoroff APT's GhostCall and GhostHire campaigns. Extensive research detailing multiple malware chains targeting macOS, including a stealer suite, fake Zoo...
securelist.com
November 23, 2025 at 8:13 PM
Kaspersky exposes new BlueNoroff campaigns targeting Web3 firms

At the Security Analyst Summit in Thailand, Kaspersky’s Global Research and Analysis Team (GReAT) revealed the latest wave of BlueNoroff APT activity through two newly identified campaigns — GhostCall and GhostHire. The sophisticated…
Kaspersky exposes new BlueNoroff campaigns targeting Web3 firms
At the Security Analyst Summit in Thailand, Kaspersky’s Global Research and Analysis Team (GReAT) revealed the latest wave of BlueNoroff APT activity through two newly identified campaigns — GhostCall and GhostHire. The sophisticated operations, active since at least April 2025, have been targeting Web3 and cryptocurrency organisations across India, Turkiye, Australia, and multiple countries in Europe and Asia. BlueNoroff, a subdivision of the notorious Lazarus Group, has expanded its long-running…
todayheadline.co
October 30, 2025 at 6:58 AM
"The axios attack is an extension of the GhostCall campaign by BlueNoroff" published by Kaspersky. #Axios, #BlueNoroff, #NPM, #GhostCall, #SysPhon, #DPRK, #CTI https://archive.md/mRArP
April 9, 2026 at 1:30 PM
"North Korea’s “Prospect Call” Trap: Lazarus Turns Teams Meetings into macOS Credential Theft" published by Daylight. #BlueNoroff, #GhostCall, #DPRK, #CTI https://daylight.ai/blog/prospect-call-microsoft-teams-meetings
February 2, 2026 at 1:30 PM